Description
Pay2Key is a C++ ransomware family that the Fox Kitten threat actor has used since at least July 2020, including campaigns against Israeli companies. Its operations pair encryption with a leak site that displays stolen sensitive information to pressure victims into paying.
Stats
- First seen
- May 2022
- Last seen
- October 2026
Also known as
Pay2key
MITRE ATT&CK techniques
8 techniques across 4 tactics.
TA0011 Command and Control
Associated groups
Alert name variants
| Alert Name |
|---|
| Document-HTML.Trojan.Pay2key |
| Gen:Variant.Ransom.Pay2Key.1 |
| Gen:Variant.Ransom.Pay2Key.4 |
| Win32.Ransomware.Pay2key |
| Win32.Ransomware.Pay2Key |
| Win32.Trojan.Pay2key |