The Rise of Pay2Key.I2P: A New Threat in Cybersecurity
Introduction to Pay2Key.I2P
The world of ransomware has seen significant shifts, especially with the emergence of Pay2Key, a ransomware-as-a-service (RaaS) that has resurfaced amidst rising geopolitical tensions involving Iran, Israel, and the United States. Operating under the name Pay2Key.I2P, this service offers enticing financial incentives for cybercriminals targeting entities linked to these nations.
Connections to Fox Kitten and Ideological Motivations
Recent analyses suggest that Pay2Key.I2P is affiliated with the hacking group known as Fox Kitten, also referred to as Lemon Sandstorm. According to Morphisec security researcher Ilia Kulmin, this group has expanded its operations by drawing on capabilities from the established Mimic ransomware. One particularly noteworthy aspect of this arrangement is the profit-sharing model; affiliates of Pay2Key.I2P can earn an impressive 80% from successful attacks, a significant jump from the previous 70%. This increase highlights the group’s ideological commitment to supporting Iran and its adversaries.
Historical Context and Operational Tactics
Pay2Key’s roots trace back to October 2020, when it predominantly targeted Israeli firms by exploiting well-known security vulnerabilities. As of February 2025, Pay2Key.I2P had reportedly executed over 51 successful ransom operations within just four months, amassing more than $4 million in total ransoms and individual operators reportedly pocketing around $100,000.
This RaaS operation is not solely driven by profit; it appears to have an underlying mission that aligns with broader cyber warfare objectives against Israel and the U.S. By combining financial gain with ideological motives, Pay2Key.I2P stands as a significant threat in the realm of cybersecurity.
A Novel Hosting Platform: The Invisible Internet Project
One of the most striking features of Pay2Key.I2P is its operation on the Invisible Internet Project (I2P). While some malware has previously utilized I2P for command-and-control communications, this marks a groundbreaking development. According to Swiss cybersecurity firm PRODAFT, Pay2Key.I2P is the first RaaS to run its entire infrastructure on this platform. This move adds an extra layer of complexity for cybersecurity teams trying to combat it.
Innovative Payment Structures
The payment structure associated with Pay2Key.I2P represents a notable shift in RaaS models. Rather than simply earning a percentage from ransomware sales, this setup allows developers to retain a significant portion of the ransom. Attackers are incentivized to successfully deploy the ransomware, creating a decentralized ecosystem that rewards successful intrusions.
Expanding Targets and Capabilities
As of June 2025, the ransomware builder has included new features, such as options to target Linux systems in addition to Windows. This indicates a concerted effort to enhance the RaaS’s effectiveness and reach. The Windows variant is typically distributed as a self-extracting executable, allowing it to infiltrate systems more seamlessly.
Evasion Techniques
Pay2Key.I2P incorporates numerous evasion techniques to avoid detection, including disabling Microsoft Defender Antivirus and eliminating any digital footprints left in the wake of an attack. By adopting such stealthy methodologies, Pay2Key.I2P aims to minimize the potential for forensic analysis following an attack.
Attack Vectors and Infection Strategies
Recent reports from SonicWall Capture Labs reveal that Pay2Key.I2P employs portable executables masquerading as Microsoft Word documents to initiate infections. The process typically involves launching command-line files that trigger the encryption phase and deploy ransom notes, showcasing a sophisticated approach to cyber infiltration.
The Bigger Picture of Cyber Warfare
Morphisec describes Pay2Key.I2P as indicative of a dangerous intersection between Iranian state-sponsored cyber activities and global cybercrime. With strong affiliations to the Fox Kitten and Mimic groups, an 80% profit incentive for Iranian supporters, and significant financial gains, this RaaS poses a substantial threat to Western organizations that find themselves in the crosshairs of this evolving cyber warfare landscape.
Call to Vigilance in Cybersecurity
In light of this rising threat, U.S. cybersecurity and intelligence agencies have cautioned against potential backlash from Iranian groups, particularly following recent American airstrikes on Iranian nuclear facilities. Industry experts, including those from operational technology security firm Nozomi Networks, urge industrial and critical infrastructure organizations to remain alert and reassess their security measures. The firm reported detecting 28 cyber attacks from Iranian-affiliated threat actors between May and June 2025.
By understanding the evolving tactics, motivations, and infrastructures employed by ransomware groups like Pay2Key.I2P, organizations can better prepare themselves against the threats posed by cybercriminals operating within this shadowy realm.


