logo

Inside Pay2Key: Technical Analysis of a Linux Ransomware Variant 

ID: fe480815-52c6-58fa-9f86-9eb85356505b

STIX ID: report--fe480815-52c6-58fa-9f86-9eb85356505b

Feed Name: Morphisec Blog

Threat Score
70/100

Date Published: 2026-03-24

Date Updated: 2026-07-20

...
...

Pay2Key's Linux ransomware variant is analyzed in depth, showing a root-privileged, configuration-driven encryptor that enumerates mounts, disables defenses (stops services, kills processes, disables SELinux/AppArmor), persists via cron, and encrypts files using ChaCha20 with full or sampled modes; the report notes per-file key obfuscation, lack of observed C2 or exfiltration, and defensive recommendations for Linux environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.