logo

Iran-Linked Pay2Key Ransomware Group Re-Emerges

ID: 691f3407-a4ae-58a9-8179-04accb9a6bd6

STIX ID: report--691f3407-a4ae-58a9-8179-04accb9a6bd6

Feed Name: Infosecurity Magazine (News)

Threat Score
78/100

Date Published: 2026-03-26

Date Updated: 2026-04-22

...
...

A new Halcyon/Beazley analysis describes a Pay2Key ransomware attack on a US healthcare provider that demonstrates enhanced evasion and anti-forensics: actors gained interactive access (TeamViewer), harvested credentials (Mimikatz, LaZagne, ExtPassword), scanned the network and interacted with Active Directory, enumerated backup solutions, and executed ransomware via a self-extracting 7zip (abc.exe), encrypting the target infrastructure in about three hours; the report notes political motivations, unclear ownership, ~$8M in ransoms tied to 170 victims, and advises ongoing monitoring and intelligence sharing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.