Pay2Key

MITRE ATT&CK: S0556 View on attack.mitre.org

Aliases: Cobalt, Pay2Key

First seen
2020-07-01 00:00:00
Malware type
ransomware
Family
Malware family
Operating systems
windows
Related IoCs
971 (850 malicious)
Last IoC activity
2026-09-01 23:46:19
Profile updated
2026-07-07 12:38:43

Targeted industries: government-and-public-sector professional-services financial-services

Targeted regions: country_code:il

Context

Pay2Key is a ransomware written in C++ that has been used by Fox Kitten since at least July 2020 including campaigns against Israeli companies. Pay2Key has been incorporated with a leak site to display stolen sensitive information to further pressure victims into payment.

Recent IoC activity

850 malicious indicators in Maltiverse are attributed to Pay2Key (S0556). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname safe-dns.it.com 2026-09-02 1
IP address 179.43.186.214 2026-08-19 5
file sample file 2026-06-17 2
hostname wiresguard.com 2026-05-20 1
file sample f7130464821513644ab5aa4b495126f7ae62e56f10d300d7ca73fb9561211695.bin 2026-03-31 1
URL http://165.154.125.212:8080/02.08.2022.exe 2026-01-14 2
URL http://179.43.186.214/SMPl 2025-12-25 1
URL https://179.43.186.214:7889/QXjI 2025-12-25 1
URL http://179.43.186.214/IMcc 2025-12-25 1
URL http://179.43.186.214/RkMR 2025-12-25 1
URL https://179.43.186.214:7889/RkMR 2025-12-25 1
URL https://179.43.186.214:7889/ky5C 2025-12-25 1
URL https://179.43.186.214:7889/SMPl 2025-12-25 1
URL http://179.43.186.214/w6Cl 2025-12-25 1
URL http://179.43.186.214/cNdG 2025-12-25 1
URL http://179.43.186.214/yD9f 2025-12-25 1
URL http://179.43.186.214/ZhMM 2025-12-25 1
URL https://179.43.186.214:7889/ONmR 2025-12-25 1
URL https://179.43.186.214:7889/Eu8j 2025-12-25 1
URL http://179.43.186.214/ONmR 2025-12-25 1

Detection coverage

  • 5 YARA rules
  • 91 Sigma rules

Malware & tools used

  • Internal Proxy (attack-pattern)
  • Asymmetric Cryptography (attack-pattern)
  • Service Stop (attack-pattern)
  • File Deletion (attack-pattern)
  • Non-Application Layer Protocol (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Data Encrypted for Impact (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)

Used by threat actors

  • Fox Kitten (threat-actor)
  • 2023 Increased Truebot Activity (campaign)
  • C0015 (campaign)
  • FIN12 March 2023 Hospital Center Intrusion (campaign)
  • May 2023 Exfiltration & Wiper Activity (Truebot + FlawedGrace + MBR Killer) (campaign)
  • PaperCut Vulnerability Exploitation (campaign)
  • Pikabot Distribution Campaigns 2023 (campaign)
  • Quantum Ransomware Compromise (campaign)
  • Water Curupira Pikabot Distribution (campaign)

Detection rules

  • ARKBIRD_SOLG_Ran_Pay2Key_Nov_2020_1 (yara-rule)
  • EMBEERESEARCH_Win_Cobalt_Sleep_Encrypt (yara-rule)
  • EMBEERESEARCH_Win_Cobalt_Strike_Loader_Shellcode_Jun_2023 (yara-rule)
  • MALPEDIA_Win_Cobalt_Strike_Auto (yara-rule)
  • MALPEDIA_Win_Pay2Key_Auto (yara-rule)

Reports & references

  • pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
  • CrowdStrike — Report2021Gtr (report)
  • clearskysec.com — Fox Kitten (report)
  • clearskysec.com — Pay2Kitten (report)
  • docs.google.com — 1Mi8Z2Tbhmqq5X8Wf Ozv3Dvjz5Sjos 3 (report)
  • research.checkpoint.com — Ransomware Alert Pay2Key (report)
  • twitter.com — P2Ktwtacc (report)
  • keybase.io — Pay2Key (report)
  • twitter.com — 1389422784808378370 (report)
  • bleepingcomputer.com — Intels Habana Labs Hacked By Pay2Key Ransomware Data Stolen (report)
  • ransomlook.io — Pay2Key (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Pay2Key (report)
  • MITRE ATT&CK — S0556 (report)

External references