Linux Ransomware Pay2Key Targets Servers, Virtualization Hosts, and Cloud Workloads
ID: 2c03c0cd-8b9f-5c1d-8b25-63d3a04ab1a1
STIX ID: report--2c03c0cd-8b9f-5c1d-8b25-63d3a04ab1a1
Feed Name: GBHackers
Pay2Key has evolved into a Linux-capable ransomware-as-a-service that actively targets enterprise Linux servers, VMware ESXi hypervisors, and cloud/container workloads; the Linux build requires root, disables protections (SELinux/AppArmor), kills services, installs cron persistence, filters mounts, and uses ChaCha20 per-file encryption with obfuscated metadata—enabling high-impact, scalable attacks and complicating recovery—while reported links to Iranian-backed actors and RaaS affiliate models increase the operational risk and call for strengthened access controls, segmentation, and purpose-built Linux defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
