logo

Linux Ransomware Pay2Key Targets Servers, Virtualization Hosts, and Cloud Workloads

ID: 2c03c0cd-8b9f-5c1d-8b25-63d3a04ab1a1

STIX ID: report--2c03c0cd-8b9f-5c1d-8b25-63d3a04ab1a1

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-03-25

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Pay2Key has evolved into a Linux-capable ransomware-as-a-service that actively targets enterprise Linux servers, VMware ESXi hypervisors, and cloud/container workloads; the Linux build requires root, disables protections (SELinux/AppArmor), kills services, installs cron persistence, filters mounts, and uses ChaCha20 per-file encryption with obfuscated metadata—enabling high-impact, scalable attacks and complicating recovery—while reported links to Iranian-backed actors and RaaS affiliate models increase the operational risk and call for strengthened access controls, segmentation, and purpose-built Linux defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.