New Iranian-Backed Pay2Key Ransomware Offers Cybercriminals 80% Profit Share

Published:

spot_img

The Rise of Pay2Key.I2P: A New Threat in Cybersecurity

Introduction to Pay2Key.I2P

The world of ransomware has seen significant shifts, especially with the emergence of Pay2Key, a ransomware-as-a-service (RaaS) that has resurfaced amidst rising geopolitical tensions involving Iran, Israel, and the United States. Operating under the name Pay2Key.I2P, this service offers enticing financial incentives for cybercriminals targeting entities linked to these nations.

Connections to Fox Kitten and Ideological Motivations

Recent analyses suggest that Pay2Key.I2P is affiliated with the hacking group known as Fox Kitten, also referred to as Lemon Sandstorm. According to Morphisec security researcher Ilia Kulmin, this group has expanded its operations by drawing on capabilities from the established Mimic ransomware. One particularly noteworthy aspect of this arrangement is the profit-sharing model; affiliates of Pay2Key.I2P can earn an impressive 80% from successful attacks, a significant jump from the previous 70%. This increase highlights the group’s ideological commitment to supporting Iran and its adversaries.

Historical Context and Operational Tactics

Pay2Key’s roots trace back to October 2020, when it predominantly targeted Israeli firms by exploiting well-known security vulnerabilities. As of February 2025, Pay2Key.I2P had reportedly executed over 51 successful ransom operations within just four months, amassing more than $4 million in total ransoms and individual operators reportedly pocketing around $100,000.

This RaaS operation is not solely driven by profit; it appears to have an underlying mission that aligns with broader cyber warfare objectives against Israel and the U.S. By combining financial gain with ideological motives, Pay2Key.I2P stands as a significant threat in the realm of cybersecurity.

A Novel Hosting Platform: The Invisible Internet Project

One of the most striking features of Pay2Key.I2P is its operation on the Invisible Internet Project (I2P). While some malware has previously utilized I2P for command-and-control communications, this marks a groundbreaking development. According to Swiss cybersecurity firm PRODAFT, Pay2Key.I2P is the first RaaS to run its entire infrastructure on this platform. This move adds an extra layer of complexity for cybersecurity teams trying to combat it.

Innovative Payment Structures

The payment structure associated with Pay2Key.I2P represents a notable shift in RaaS models. Rather than simply earning a percentage from ransomware sales, this setup allows developers to retain a significant portion of the ransom. Attackers are incentivized to successfully deploy the ransomware, creating a decentralized ecosystem that rewards successful intrusions.

Expanding Targets and Capabilities

As of June 2025, the ransomware builder has included new features, such as options to target Linux systems in addition to Windows. This indicates a concerted effort to enhance the RaaS’s effectiveness and reach. The Windows variant is typically distributed as a self-extracting executable, allowing it to infiltrate systems more seamlessly.

Evasion Techniques

Pay2Key.I2P incorporates numerous evasion techniques to avoid detection, including disabling Microsoft Defender Antivirus and eliminating any digital footprints left in the wake of an attack. By adopting such stealthy methodologies, Pay2Key.I2P aims to minimize the potential for forensic analysis following an attack.

Attack Vectors and Infection Strategies

Recent reports from SonicWall Capture Labs reveal that Pay2Key.I2P employs portable executables masquerading as Microsoft Word documents to initiate infections. The process typically involves launching command-line files that trigger the encryption phase and deploy ransom notes, showcasing a sophisticated approach to cyber infiltration.

The Bigger Picture of Cyber Warfare

Morphisec describes Pay2Key.I2P as indicative of a dangerous intersection between Iranian state-sponsored cyber activities and global cybercrime. With strong affiliations to the Fox Kitten and Mimic groups, an 80% profit incentive for Iranian supporters, and significant financial gains, this RaaS poses a substantial threat to Western organizations that find themselves in the crosshairs of this evolving cyber warfare landscape.

Call to Vigilance in Cybersecurity

In light of this rising threat, U.S. cybersecurity and intelligence agencies have cautioned against potential backlash from Iranian groups, particularly following recent American airstrikes on Iranian nuclear facilities. Industry experts, including those from operational technology security firm Nozomi Networks, urge industrial and critical infrastructure organizations to remain alert and reassess their security measures. The firm reported detecting 28 cyber attacks from Iranian-affiliated threat actors between May and June 2025.


By understanding the evolving tactics, motivations, and infrastructures employed by ransomware groups like Pay2Key.I2P, organizations can better prepare themselves against the threats posed by cybercriminals operating within this shadowy realm.

spot_img

Related articles

Recent articles

Origin Energy Data Breach 2026: Unauthorized Access Exposes PII of 900,000 Customers

On July 28, 2026, Origin Energy confirmed a significant data breach impacting approximately 900,000 current and former customers. This incident involved unauthorized access and...

Mirage Kitten Unveils NightLedger Backdoor and WebSocket Tunnelers for Cyber-Espionage in Middle East and Africa

Recent research has unveiled a new set of malware tools attributed to the advanced persistent threat (APT) group known as Mirage Kitten, which is...

Bank of Baroda Reports Cybersecurity Incident Following Alleged Data Theft Claims

Bank of Baroda, one of India's largest state-owned banks, has reported a cybersecurity incident following claims from a threat actor regarding the theft and...

Fairlife resumes US production after ransomware attack, data breach confirmed

USA – The Coca-Cola Company has announced that its dairy subsidiary Fairlife has resumed most production across its four US facilities following a ransomware...