Pay2Key's Resurgence: Iranian Cyber Warfare Targets the West
July 13, 2025, 12:04 p.m.
Description
Pay2Key, an Iranian-backed ransomware-as-a-service operation, has re-emerged as Pay2Key.I2P, targeting Western organizations. Linked to the Fox Kitten APT group and collaborating with Mimic ransomware, the campaign has collected over $4 million in ransom payments in four months. The group offers an 80% profit share to affiliates supporting Iran or attacking its enemies, blending financial motivations with geopolitical objectives. Pay2Key.I2P employs sophisticated evasion techniques, including anti-analysis checks and obfuscation methods. The operation's strategic marketing on darknet forums and social media platforms indicates a planned rollout, with the addition of Linux-targeted ransomware expanding their attack surface.
Tags
Date
- Created: July 10, 2025, 6:31 p.m.
- Published: July 10, 2025, 6:31 p.m.
- Modified: July 13, 2025, 12:04 p.m.
Indicators
- f947771556e0a0d900b21de6a37abd04c1d2e0e84d0062f61c49d792ffedeec5
- e237cf378e2848f687a494ab67faf9e7ec784d00090cd598a9f1e3291c97181f
- d8e423c8644b686ad3376f38f3e4df55a152ee4cac2af3079651263f002d8c26
- d61a55d368a1dcf570f633c7a23ae12361749c2d7000178dd9e353528c325907
- bd4635d582413f84ac83adbb4b449b18bac4fc87ca000d0c7be84ad0f9caf68e
- b64305852ddb317b7839b39db602fcdda60e7658f391ff4ba52fce4dbca89089
- a8bfa1389c49836264cfa31fc4410b88897a78d9c2152729d28eca8c12171b9e
- a05c18e81911608cf2edb19907092d542548abb695e48e3217dfbec2f3dfcd04
- 9c06ea83553c6dab3d831e1046cee237a9c1b1ed79b3b2e37ed9f3c8a38643eb
- 89ad2164717bd5f5f93fbb4cebf0efeb473097408fddfc7fc7b924d790514dc5
- 791bb67fe91e9bd129607a94714e9e79afe304271d839b369aab8813d2da4ac1
- 7336b865f232f7fccb9b85524d5ebdc444344de363f77e1b1c3eaeeb3428e1a5
- 6f0b01ceb4e2cfbdfe8b92729f18eb7f4953bf9859085dc3ac81983274065d6c
- 65be56f46b2aa6bb64b9e560a083a77a80a1b5a459bcba8d385aa62f8e7b153f
- 3ba64d08edbfadec8e301673df8b36f9f7475c83587930fc9577ea366ec06839
- 60ec008c8515934c3c8d89f84bbcc8fac9144e642c0143d8230f465f4e66f62c
- 39d3ba87a27eae69a01666b0ecbb8c60259be4b3decf4cdd1d950c98c6c0b08c
- 2fefb69e4b2310be5e09d329e8cf1bebd1f9e18884c8c2a38af8d7ea46bd5e01
- 242fa471582c2f37c17717dc260cb108584c44e86b8831382f7b2f5fc63aeb6b
- 1d0ec8e34703a7589533462be62c020004cfe0f7b20204f9e6c79b84cbfafc9b
- 1c70d4280835f18654422cec1b209eec856f90344b8f02afca82716555346a55
- 1c3f2530b2764754045039066d2c277dff4efabd4f15f2944e30b10e82f443c0
- 188c215fa32a445d7ffa90dc51c58bddcd62a714a8f6eac89b92574c349bf901
- 17fc4df8ef9a92c972684cba707c3976b91bcd7f0251f42f1b63e4de0e688d6c
- gos-usa.xyz