Pay2Key Alert! Israel Firms Targeted with New Ransomware

Date:

Share post:

Multiple organizations in Israel have reported several cyberattacks in which attackers targeted them using a new strain of ransomware named “Pay2Key”. According to CheckPoint research, threat actors illicitly obtained the foothold and remotely controlled the infection within the compromised networks. The Pay2Key ransomware is written in C++ and compiled using MSVC++ 2015. It also makes use of third-party libraries like Boost.

“The investigation so far indicates the attacker may have gained access to the organizations’ networks some time before the attack but presented an ability to make a rapid move of spreading the ransomware within an hour to the entire network. After completing the infection phase, the victims received a customized ransom note, with a relatively low demand of 7-9 bitcoins (~$110K-$140K),” the researchers said.

Key findings:

  • Previously unknown ransomware dubbed Pay2Key, carries targeted attacks against Israeli companies
  • Initial infection is presumably made through RDP connection
  • Lateral movement is made using psexec.exe to execute the ransomware on the different machines within the organization
  • Special attention was given to the design of the network communication in order to reduce the noise a large number of encrypted machines may generate while contacting the Command and Control servers
  • The encryption scheme is solid – using the AES and RSA algorithms

“While the attack is still under investigation, the recent Pay2Key ransomware attacks indicate a new threat actor is joining the trend of targeted ransomware attacks – presenting well designed operation to maximize damage and minimize exposure. The attack was observed targeting the Israeli private sector so far, but looking at the presented tactics, techniques, and procedures we see a potent actor who has no technical reason to limit his targets list to Israel. The incidents are still under investigation, and we will update this blogpost with new findings if any new findings come to light,” the researchers added.

Subscribe

Name(Required)
Privacy(Required)

Upcoming Events

Related articles

Stop Reviewing Faster: A Practical Model for AppSec at AI Speed

By Aparna Ash Himmatramka A developer using an AI assistant can ship a feature in an afternoon. In many...

Why I Go to the Dark Web Every Day

By Alex Holden, Chief Information Security Officer Hold Security For nearly two decades I made the Dark Web a...

The Cyber Security EXPO is the only dedicated recruitment event for Cyber Security Professionals

Located in the heart of London at the QEII Centre, the Cyber Security EXPO London offers a prime...

Atlanta Set to Host Hacker Halted and Global CISO Forum 2026, Uniting Practitioners and C-Suite Leaders

The Westin Peachtree Plaza will anchor a week of hands-on training, offensive security research, and closed-door executive dialogue...