Netskope Threat Labs

Pay2Key

ATP Sandbox Adv. HeuristicsAV

Pay2Key is a C++ ransomware family that the Fox Kitten threat actor has used since at least July 2020, including campaigns against Israeli companies. Its operations pair encryption with a leak site that displays stolen sensitive information to pressure victims into paying.

First seen
May 2022
Last seen
October 2026
Pay2key

8 techniques across 4 tactics.

TA0005 Stealth

TA0007 Discovery

  • T1016System Network Configuration Discovery
  • T1082System Information Discovery

TA0011 Command and Control

TA0040 Impact

Alert Name
Document-HTML.Trojan.Pay2key
Gen:Variant.Ransom.Pay2Key.1
Gen:Variant.Ransom.Pay2Key.4
Win32.Ransomware.Pay2key
Win32.Ransomware.Pay2Key
Win32.Trojan.Pay2key