Pay2Key

S0556

Malware.View on attack.mitre.org

About this malware

Pay2Key is a ransomware written in C++ that has been used by Fox Kitten since at least July 2020 including campaigns against Israeli companies. Pay2Key has been incorporated with a leak site to display stolen sensitive information to further pressure victims into payment.

Techniques used8

Procedure examples8

TechniqueProcedure example
T1016
System Network Configuration Discovery

Pay2Key can identify the IP and MAC addresses of the compromised host.

T1070.004
File Deletion

Pay2Key can remove its log file from disk.

T1082
System Information Discovery

Pay2Key has the ability to gather the hostname of the victim machine.

T1090.001
Internal Proxy

Pay2Key has designated machines in the compromised network to serve as reverse proxy pivot points to channel communications with C2.

T1095
Non-Application Layer Protocol

Pay2Key has sent its public key to the C2 server over TCP.

T1486
Data Encrypted for Impact

Pay2Key can encrypt data on victim's machines using RSA and AES algorithms in order to extort a ransom payment for decryption.

T1489
Service Stop

Pay2Key can stop the MS SQL service at the end of the encryption process to release files locked by the service.

T1573.002
Asymmetric Cryptography

Pay2Key has used RSA encrypted communications with C2.

Groups that use it1

Campaigns0

None recorded.

References2

  1. Check Point Pay2Key November 2020 Open source
    Check Point. (2020, November 6). Ransomware Alert: Pay2Key. Retrieved January 4, 2021.
  2. ClearkSky Fox Kitten February 2020 Open source
    ClearSky. (2020, February 16). Fox Kitten – Widespread Iranian Espionage-Offensive Campaign. Retrieved December 21, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.