Pay2Key is ransomware that has been used by the threat actor Fox Kitten. The group seems to operate since July 2020, targetting mainly Israeli companies. Pay2Key has a darknet leak site to public stolen and sensitive information of their victims. Some of their victims: Intel - Habana Labs, IAI - Israel Aerospace Industries, Portnox - Network Security Solutions. Known victims: 7
Objectives
Executive Summary
The pay2key ransomware is used by the Fox Kitten threat actor, primarily targeting Israeli companies since July 2020. The group operates a darknet leak site to publish sensitive information of their victims, including Intel's Habana Labs and Israel Aerospace Industries. Their primary goal is financial gain through ransom demands.
Goals & Targeting
The Fox Kitten threat actor's strategic objectives appear to be primarily focused on achieving financial gain through ransom demands. They target Israeli companies, likely due to the perceived likelihood of payment, and seek to steal sensitive information that can be used to extort payment. Their typical victims are companies in the tech and aerospace sectors, although they may also target other organizations that they believe will be willing to pay a ransom.
Enhanced Description
The Pay2Key ransomware is likely just one tool in the Fox Kitten threat actor's arsenal, and the group may use a range of other tactics and techniques to achieve their goals. However, the fact that they have been able to successfully use Pay2Key to extort payment from multiple victims suggests that they are a formidable opponent, and that organizations should be taking steps to protect themselves against this threat. This may include implementing robust security controls, such as backups and encryption, as well as providing training to employees on how to avoid falling victim to phishing and other social engineering attacks.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The Fox Kitten threat actor's campaign patterns suggest a focus on targeting Israeli companies, with a range of victims across the tech and aerospace sectors. Their operational tempo appears to be relatively slow, with a focus on carefully selecting and targeting specific organizations. Notable past operations include the targeting of Intel's Habana Labs and Israel Aerospace Industries, and the group may continue to target similar organizations in the future.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level in the available data is medium-high, based on the fact that the threat actor has been active for over a year and has successfully targeted multiple victims. However, there are some information gaps, including a lack of detailed information on the threat actor's TTPs and the full range of their capabilities.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics