logo

Iranian ransomware crew reemerges, promises big bucks for attacks on US or Israel

ID: 0f73e964-38bf-5ca7-8b3a-400b91a215f2

STIX ID: report--0f73e964-38bf-5ca7-8b3a-400b91a215f2

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2025-07-09

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Pay2Key.I2P, an updated Pay2Key ransomware-as-a-service with links to Iran's Pioneer Kitten and shared capabilities with Mimic ransomware, has resurfaced after a five-year hiatus and is actively targeting US and Israeli organizations. The group advertises higher payouts for attacks against those countries, hosts leak sites on the I2P network, added a Linux build, and claims roughly $4 million in proceeds from about 50 ransom payments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.