pay2key
Pay2Key is an Iran-linked ransomware operation active since 2020 and described in the reporting as aligned with Iranian state interests, with ties to the Iranian government and to the Iranian state-sponsored group Fox Kitten (UNC757). It has been characterized as a ransomware-as-a-service (RaaS) operation and as an Iranian state-backed ransomware operation. Reporting also notes recruitment of affiliates on Russian cybercriminal forums, marketing on Russian and Chinese dark web forums, possible ties to Russian-speaking threat actors, and uncertainty around ownership and operational control after the group reportedly attempted to sell the operation in late 2025. Historically, Pay2Key was associated with attacks on Israeli organizations, including hack-and-leak and data-wiping activity. More recent reporting says the group shifted toward Western targets and offered increased affiliate revenue share for attacks against "the enemies of Iran," particularly the United States and Israel. In late February 2026, Pay2Key targeted a U.S. healthcare organization. Halcyon and Beazley Security reported the actors had compromised an administrative account, remained in the environment for several days, used TeamViewer for interactive access, harvested credentials with Mimikatz, LaZagne, and ExtPassword, performed network discovery with tools including Advanced IP Scanner and a tool believed to be NetScan, interacted with Active Directory via dsa.msc, enumerated backup software, disabled Microsoft Defender using a "No Defender" toolkit, inhibited recovery, deployed ransomware through a self-extracting 7zip archive named abc.exe, encrypted the environment in about three hours, and cleared logs afterward. Multiple reports state no evidence of data exfiltration was found in that incident, and researchers assessed the operation appeared more destructive than financially motivated. Pay2Key has been reported to use enhanced evasion, execution, anti-forensics, and anti-detection capabilities in newer variants. Reporting also describes a Linux variant, Pay2Key.I2, first detected in the wild in late August 2025, targeting organizational servers, virtualization hosts, and cloud workloads. That Linux build reportedly requires root privileges, disables SELinux and AppArmor, kills services and processes, persists via cron, enumerates mounted filesystems, and uses ChaCha20 encryption. Separate analysis of a January 2026 Windows build described it as Mimic/Conti-derived, delivered in a self-extracting 7z archive, using Everything APIs for file enumeration, Restart Manager for file unlocking, and ChaCha20 plus Curve25519-based key protection. The content also states Pay2Key has targeted organizations in the United States, Israel, Azerbaijan, and the United Arab Emirates. Known aliases and related names directly mentioned in the content include Pay2Key.I2, Pay2Key.I2P, and Fox Kitten (UNC757) as a linked Iranian threat group.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Health Care Equipment & Services
Where they target
Geographies tied to known operations.
- 🇺🇸 United States
- 🇮🇱 Israel
Where they're from
Attributed origin per open-source reporting.
- IR
Tradecraft
29 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Observables
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Iran-linked ransomware operation targeting US healthcare with disruptive and strategic objectives.
Iranian-government-linked ransomware activity targeting a US healthcare organization, with access established before attack and ransomware deployed rapidly; described as more destructive than financially motivated in this case.
An Iranian ransomware-as-a-service operation tied to the Iranian government and Fox Kitten, targeting a U.S. healthcare organization and using improved evasion, execution, and anti-forensics techniques. The group historically used double extortion, though no data was exfiltrated in this incident.
An Iranian state-backed ransomware operation being revived to attack high-impact US targets, recruit affiliates from Russian cybercriminal forums, and support Iran's geopolitical objectives through ransomware, pseudo-ransomware, and profit-sharing incentives.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.