LIVE NEWS
  • Trinidad and Tobago police uncover 56 bodies, mostly children, at cemetery | Crime News
  • The best TV antennas to buy in 2024
  • Look beyond Trump for the real story on US climate action
  • Obama meets Mamdani in New York City before reading to preschoolers
  • How Trump is pushing psychedelics reform through the health agencies
  • Now is your last chance to grab our EXCLUSIVE Surfshark deal — year-low prices with 4 months extra protection included
  • Middle East crisis live: ships report attacks as Iran closes strait of Hormuz; Trump reportedly convenes Situation Room meeting | US-Israel war on Iran
  • 50,640 People Affected After Hackers Hit Healthcare Firm, Stealing Personal, Financial and Medical Data
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Cybersecurity»Iran-Linked Pay2Key Ransomware Group Re-Emerges
Cybersecurity

Iran-Linked Pay2Key Ransomware Group Re-Emerges

primereportsBy primereportsMarch 26, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Iran-Linked Pay2Key Ransomware Group Re-Emerges
Share
Facebook Twitter LinkedIn Pinterest Email


Security experts have warned that an Iranian ransomware group has returned with enhanced evasion, execution and anti-forensics capabilities.

Previously linked to Tehran and usually targeting victims aligned with the regime’s interests, Pay2Key has been active since 2020.

However, a new report from Halcyon and Beazley Security warned that “recent US-Iran tensions appear to have accelerated activity from the group.”

The report dissected a new attack on a US healthcare provider which appeared to show an evolving set of TTPs.

Read more on Pay2Key: Suspected Iranian Ransomware Group Targets Israeli Firms

It’s unclear whether the group bought access from an initial access broker or performed reconnaissance on the victim itself. However, with a foothold in the network, the actors used TeamViewer to establish “interactive access” and then began harvesting passwords for lateral movement, using Mimikatz, LaZagne, and ExtPassword.

They then used “Advanced IP Scanner” and ns.exe (presumed to be NetScan) to find hosts and validate credentials, the report explained.

“The threat actors used harvested credentials to pivot across systems, and interacted with Active Directory via dsa.msc, the built-in AD ‘Users and Computers’ console. We believe this was to prevent tooling from automatically flagging the access as anomalous or suspicious,” it continued.

“We believe this was used to identify accounts to be used in concert with ransomware deployment as well as accessing an assortment of backup-related software on victim hosts. Backup systems enumerated include IBackup, Barracuda Yosemite, and Windows Server Backup.”

Ransomware execution was performed through a self-extracting 7zip archive (SFX), abc.exe, which is consistent with previous campaigns. Encryption of the entire infrastructure took just three hours.

The group also deployed a “No Defender” evasion toolkit, which it then removed to hide its tracks.

There was no evidence of data exfiltration, which the report authors claimed “could be due to targeted destruction of evidence by the group.”

Questions Over Iran Links

The attack follows a previous campaign analyzed by Morphisec that coincided with US missile strikes on Iran last year. Since July 2025, the group has received more than $8m in ransom payments linked to 170 victims.

This could indicate that Pay2key remains an Iranian-linked operation whose attacks intensify during periods of geopolitical tension involving the country – but it’s not a given.

“The group’s attempted sale of its entire operation in late 2025, combined with observed ties to Russian-speaking threat actors on criminal forums, raises unresolved questions about the current ownership, operational control and future trajectory of the group’s RaaS platform,” the Halcyon report noted.

Whatever the ownership, however, network defenders should be aware of the threat it poses, the report concluded.

“The group does not always appear to prioritize extortion and financial gain over the destruction of victim environments for strategic impact,” it said.

“Defenders should treat these findings as a clear signal that Pay2Key remains an active, unpredictable, and politically motivated threat whose tactics and objectives warrant ongoing monitoring and proactive intelligence sharing across the security community.”

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleAnthropic Releases The World’s Largest Study On Global AI Attitudes
Next Article The Death of APR as a Metric
primereports
  • Website

Related Posts

Cybersecurity

[Webinar] Eliminate Ghost Identities Before They Expose Your Enterprise Data

April 18, 2026
Cybersecurity

Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks

April 18, 2026
Cybersecurity

Google wipes out 602 million scam ads with Gemini on duty

April 18, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Global Resources Outlook 2024 | UNEP

December 6, 20258 Views

The D Brief: DHS shutdown likely; US troops leave al-Tanf; CNO’s plea to industry; Crowded robot-boat market; And a bit more.

February 14, 20264 Views

German Chancellor Merz faces difficult mission to Israel – DW – 12/06/2025

December 6, 20254 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Geopolitics
  • Popular Now
  • Artificial Intelligence
  • Cybersecurity
  • Crypto
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • Trinidad and Tobago police uncover 56 bodies, mostly children, at cemetery | Crime News
  • The best TV antennas to buy in 2024
  • Look beyond Trump for the real story on US climate action
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.