Pay2Key
MITRE ATT&CK: S0556 View on attack.mitre.org
Aliases: Cobalt, Pay2Key
- First seen
- 2020-07-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 971 (850 malicious)
- Last IoC activity
- 2026-09-01 23:46:19
- Profile updated
- 2026-07-07 12:38:43
Targeted industries: government-and-public-sector professional-services financial-services
Targeted regions: country_code:il
Context
Pay2Key is a ransomware written in C++ that has been used by Fox Kitten since at least July 2020 including campaigns against Israeli companies. Pay2Key has been incorporated with a leak site to display stolen sensitive information to further pressure victims into payment.
Recent IoC activity
850 malicious indicators in Maltiverse are attributed to Pay2Key (S0556). The 20 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | safe-dns.it.com | 2026-09-02 | 1 |
| IP address | 179.43.186.214 | 2026-08-19 | 5 |
| file sample | file | 2026-06-17 | 2 |
| hostname | wiresguard.com | 2026-05-20 | 1 |
| file sample | f7130464821513644ab5aa4b495126f7ae62e56f10d300d7ca73fb9561211695.bin | 2026-03-31 | 1 |
| URL | http://165.154.125.212:8080/02.08.2022.exe | 2026-01-14 | 2 |
| URL | http://179.43.186.214/SMPl | 2025-12-25 | 1 |
| URL | https://179.43.186.214:7889/QXjI | 2025-12-25 | 1 |
| URL | http://179.43.186.214/IMcc | 2025-12-25 | 1 |
| URL | http://179.43.186.214/RkMR | 2025-12-25 | 1 |
| URL | https://179.43.186.214:7889/RkMR | 2025-12-25 | 1 |
| URL | https://179.43.186.214:7889/ky5C | 2025-12-25 | 1 |
| URL | https://179.43.186.214:7889/SMPl | 2025-12-25 | 1 |
| URL | http://179.43.186.214/w6Cl | 2025-12-25 | 1 |
| URL | http://179.43.186.214/cNdG | 2025-12-25 | 1 |
| URL | http://179.43.186.214/yD9f | 2025-12-25 | 1 |
| URL | http://179.43.186.214/ZhMM | 2025-12-25 | 1 |
| URL | https://179.43.186.214:7889/ONmR | 2025-12-25 | 1 |
| URL | https://179.43.186.214:7889/Eu8j | 2025-12-25 | 1 |
| URL | http://179.43.186.214/ONmR | 2025-12-25 | 1 |
Detection coverage
- 5 YARA rules
- 91 Sigma rules
Malware & tools used
- Internal Proxy (attack-pattern)
- Asymmetric Cryptography (attack-pattern)
- Service Stop (attack-pattern)
- File Deletion (attack-pattern)
- Non-Application Layer Protocol (attack-pattern)
- System Information Discovery (attack-pattern)
- Data Encrypted for Impact (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
Used by threat actors
- Fox Kitten (threat-actor)
- 2023 Increased Truebot Activity (campaign)
- C0015 (campaign)
- FIN12 March 2023 Hospital Center Intrusion (campaign)
- May 2023 Exfiltration & Wiper Activity (Truebot + FlawedGrace + MBR Killer) (campaign)
- PaperCut Vulnerability Exploitation (campaign)
- Pikabot Distribution Campaigns 2023 (campaign)
- Quantum Ransomware Compromise (campaign)
- Water Curupira Pikabot Distribution (campaign)
Detection rules
- ARKBIRD_SOLG_Ran_Pay2Key_Nov_2020_1 (yara-rule)
- EMBEERESEARCH_Win_Cobalt_Sleep_Encrypt (yara-rule)
- EMBEERESEARCH_Win_Cobalt_Strike_Loader_Shellcode_Jun_2023 (yara-rule)
- MALPEDIA_Win_Cobalt_Strike_Auto (yara-rule)
- MALPEDIA_Win_Pay2Key_Auto (yara-rule)
Reports & references
- pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
- CrowdStrike — Report2021Gtr (report)
- clearskysec.com — Fox Kitten (report)
- clearskysec.com — Pay2Kitten (report)
- docs.google.com — 1Mi8Z2Tbhmqq5X8Wf Ozv3Dvjz5Sjos 3 (report)
- research.checkpoint.com — Ransomware Alert Pay2Key (report)
- twitter.com — P2Ktwtacc (report)
- keybase.io — Pay2Key (report)
- twitter.com — 1389422784808378370 (report)
- bleepingcomputer.com — Intels Habana Labs Hacked By Pay2Key Ransomware Data Stolen (report)
- ransomlook.io — Pay2Key (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Pay2Key (report)
- MITRE ATT&CK — S0556 (report)