Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors pay2key

Description

Pay2Key is ransomware that has been used by the threat actor Fox Kitten. The group seems to operate since July 2020, targetting mainly Israeli companies. Pay2Key has a darknet leak site to public stolen and sensitive information of their victims. Some of their victims: Intel - Habana Labs, IAI - Israel Aerospace Industries, Portnox - Network Security Solutions. Known victims: 7

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 2 weeks ago

Executive Summary

The pay2key ransomware is used by the Fox Kitten threat actor, primarily targeting Israeli companies since July 2020. The group operates a darknet leak site to publish sensitive information of their victims, including Intel's Habana Labs and Israel Aerospace Industries. Their primary goal is financial gain through ransom demands.

Goals & Targeting

The Fox Kitten threat actor's strategic objectives appear to be primarily focused on achieving financial gain through ransom demands. They target Israeli companies, likely due to the perceived likelihood of payment, and seek to steal sensitive information that can be used to extort payment. Their typical victims are companies in the tech and aerospace sectors, although they may also target other organizations that they believe will be willing to pay a ransom.

Enhanced Description

The Pay2Key ransomware is likely just one tool in the Fox Kitten threat actor's arsenal, and the group may use a range of other tactics and techniques to achieve their goals. However, the fact that they have been able to successfully use Pay2Key to extort payment from multiple victims suggests that they are a formidable opponent, and that organizations should be taking steps to protect themselves against this threat. This may include implementing robust security controls, such as backups and encryption, as well as providing training to employees on how to avoid falling victim to phishing and other social engineering attacks.

Key Capabilities

  • Ransomware development and deployment
  • Darknet leak site operation
  • Data exfiltration and extortion
  • Social engineering and phishing

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Exfiltration

ATT&CK Techniques

T1059.003
T1055
T1566.001
T1204

Software / Tooling

Custom ransomware
Phishing kits

Campaigns & Victims

The Fox Kitten threat actor's campaign patterns suggest a focus on targeting Israeli companies, with a range of victims across the tech and aerospace sectors. Their operational tempo appears to be relatively slow, with a focus on carefully selecting and targeting specific organizations. Notable past operations include the targeting of Intel's Habana Labs and Israel Aerospace Industries, and the group may continue to target similar organizations in the future.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 over DNS using fast-flux
  • Staging infrastructure on bulletproof hosting

Recommended Actions

  • Implement robust backups and encryption
  • Provide training to employees on phishing and social engineering attacks
  • Monitor for suspicious network activity
  • Use anti-ransomware software

Suggested Tags

Ransomware
Criminal
Financial gain

Confidence Assessment

The confidence level in the available data is medium-high, based on the fact that the threat actor has been active for over a year and has successfully targeted multiple victims. However, there are some information gaps, including a lack of detailed information on the threat actor's TTPs and the full range of their capabilities.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Dec 13, 2020
Last Seen
Sep 9, 2021
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.