Ransomware Group intelligence
Pay2key
InactiveTrack Pay2key with 7 published victims and 1 known leak locations in a single intelligence view.
Overview
Pay2key is tracked by Breach House as a ransomware group with 7 published victims.
Israel is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 1h ago | pay2key2zkg7arp3kv3cuugdaqwuesifnbofun4j6yjdw5ry7zw2asid.onion |
Top Activity Sectors (3)
Typical Attacks (8)
▼How Pay2key typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via Pay2Key.
-
T1070.004 File Deletion Stealth
What they do: Pay2Key can remove its log file from disk.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1016 System Network Configuration Discovery Discovery
What they do: Pay2Key can identify the IP and MAC addresses of the compromised host.
What that means: Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems.
-
T1082 System Information Discovery Discovery
What they do: Pay2Key has the ability to gather the hostname of the victim machine.
What that means: An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture.
-
T1090.001 Internal Proxy Command and Control
What they do: Pay2Key has designated machines in the compromised network to serve as reverse proxy pivot points to channel communications with C2.
What that means: Adversaries may use an internal proxy to direct command and control traffic between two or more systems in a compromised environment.
-
T1095 Non-Application Layer Protocol Command and Control
What they do: Pay2Key has sent its public key to the C2 server over TCP.
What that means: Adversaries may use an OSI non-application layer protocol for communication between host and C2 server or among infected hosts within a network.
-
T1573.002 Asymmetric Cryptography Command and Control
What they do: Pay2Key has used RSA encrypted communications with C2.
What that means: Adversaries may employ a known asymmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol.
-
T1486 Data Encrypted for Impact Impact
What they do: Pay2Key can encrypt data on victim's machines using RSA and AES algorithms in order to extort a ransom payment for decryption.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: Pay2Key can stop the MS SQL service at the end of the encryption process to release files locked by the service.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
Victims (7)
Search, filter and paginate the victim timeline for Pay2key. Showing 1–7 of 7.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | MT-LAW [Markman&Tomashin Law Firm] id1162 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | INTER - InterElectric id1161 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | InfiApps - Joyvoo id1160 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Intel - Habana Labs id1159 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | IAI - Israel Aerospace Industries id1158 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Portnox - Network Security Solutions id1157 View details | Telecommunications | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Habana Labs id546 View details | Israel | Other | — | |
|
No additional victim description available. |
|||||