logo

Iranian Ransomware Crew Blurs the Line Between Profit and Proxy Attacks

ID: 9ce6680d-f97d-50a2-a502-2ee5c9c15b92

STIX ID: report--9ce6680d-f97d-50a2-a502-2ee5c9c15b92

Feed Name: Halcyon Blog

Threat Score
85/100

Date Published: 2025-07-09

Date Updated: 2026-04-28

...
...

Pay2Key.I2P is an active Iranian-linked Ransomware-as-a-Service operation that has reportedly collected over $4 million and executed 50+ attacks; it is incentivizing affiliates (offering up to 80% payouts) to target U.S. and Israeli organizations, appears to collaborate with other ransomware operators (including Mimic), and uses wipers disguised as ransomware—illustrating a hybrid state-aligned and financially motivated threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.