logo

Pay2Key’s New Linux Ransomware Strips Server Defenses to Hijack x64 and ARM64 Infrastructure

ID: 7f82f538-5d09-58b9-a021-f151c9c752bb

STIX ID: report--7f82f538-5d09-58b9-a021-f151c9c752bb

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-03-30

Date Updated: 2026-04-23

Author: Ddos

...
...

Morphisec Threat Labs' analysis describes Pay2Key.I2P, a sophisticated Linux ransomware variant delivered via a shell script that fingerprints CPU architecture and drops dual-architecture binaries (x64 and ARM64). The malware enforces root privileges, disables defenses (SELinux/AppArmor), creates persistence via cron jobs, stops services/processes defined in config, and uses ChaCha20 with sampled encryption to accelerate damage; the report warns this productized, maintained tool can rapidly cripple enterprise servers and recommends prevention-first controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.