Skip to content

Pay2Key

Pay2Key is an Iran-linked ransomware operation first observed in 2020 and widely associated with activity aligned to Iranian state interests.

Profile source: Mallory opens in a new tab

Pay2Key

Family profile

Pay2Key is an Iran-linked ransomware operation first observed in 2020 and widely associated with activity aligned to Iranian state interests. It has been linked by multiple researchers to Fox Kitten and described as a ransomware-as-a-service operation that has targeted Israeli organizations, later expanding to additional victims including a U.S. healthcare organization. Reported targeting has included industrial, insurance, logistics, healthcare, and broader enterprise environments, with some campaigns framed as disruptive or punitive rather than purely financially motivated.

Pay2Key has been used to encrypt servers and workstations and, in some campaigns, to steal and leak victim data for extortion pressure. Early operations against Israeli entities were associated with exploitation of exposed internet-facing systems, including VPN and remote access infrastructure, as well as RDP abuse and brute forcing. Later reporting also tied Pay2Key delivery to phishing-led intrusion chains in attacks against Russian organizations, where it appeared as a final payload delivered through loaders and droppers. Operators have also used legitimate remote access software and credential theft tooling to move through victim environments before ransomware deployment.

The malware and its surrounding tradecraft emphasize operational speed, anti-forensics, and defense evasion. Reported behaviors include identifying host IP and MAC addresses, deleting logs, self-deletion, clearing evidence after execution, disabling or impairing defensive controls, and using encrypted communications. In Windows intrusions, operators have been observed harvesting credentials, enumerating hosts and backup systems, and deploying the ransomware through self-extracting archives. Analysis of a 2026 build indicates the Windows encryptor is based on Mimic, itself derived from leaked Conti code, and uses ChaCha20 for file encryption with asymmetric protection of per-file keys. The ransomware can terminate services and processes to unlock files and accelerate impact.

Pay2Key has also evolved beyond Windows. A Linux variant has been observed targeting organizational servers, virtualization hosts, and cloud workloads. That variant requires elevated privileges, disables security frameworks, kills services and processes, enumerates mounted filesystems, persists across reboot, and encrypts data using ChaCha20. Its design indicates a focus on infrastructure-layer disruption while preserving enough system functionality to present a ransom demand.

Across reporting, Pay2Key stands out as part of the broader convergence between state-linked Iranian cyber operations and criminal ransomware tradecraft. It has been described as a vehicle for extortion, disruption, and plausible deniability, with some campaigns showing characteristics consistent with geopolitical retaliation or coercive signaling rather than conventional profit-maximizing ransomware behavior.

Capabilities

  • Brute Force
  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Extortion
  • Persistence
  • Reconnaissance

Operational record

1
YARA rules
1
Leak sites
0 available

Reported operators

Threat actors

3 named in public reporting
Fox Kitten

We estimate with medium to high confidence that Pay2Key is a new operation conducted by Fox Kitten... The Pay2Key‘s modus operandi was to execute a ransomware attack... encrypts servers and workstations, steals and leaks information.

Fluffy Wolf

When deploying the Pay2Key ransomware, the attackers employ heavy anti-forensic techniques to cover their tracks.

n3tw0rm

Early May 2021 saw another set of disruptive ransomware attacks attributed to Iran targeting Israel from the n3tw0rm ransomware group, a newly-identified threat actor with links to the 2020 Pay2Key attacks.

Exploited software

Vulnerabilities linked to Pay2Key

3 CVEs

MITRE ATT&CK

Pay2Key in ATT&CK

28 distinct techniques

Reporting

Research mentioning Pay2Key

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.