LIVE NEWS
  • DOD wants to integrate cyber in all operations, and integrate security into AI
  • Bitcoin to slump to new lows after recent sell-off, traders predict
  • House and Senate Appear Closer to Voting to End Trump’s Iran War
  • NATO’s Era of Big, Central Air Operation Centers Is Over: Commander
  • Army seeks US manufacturer to supply boots
  • A secret to making a queen bee may lie in the wax around it
  • Four sentenced to death for killing worshippers at Catholic church in Nigeria
  • Analyst Who Nailed Bitcoin 2025 Top Says He’s Accumulating BTC Despite Expecting Lower Prices – Here’s His Outlook
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Cybersecurity»Iran-Linked Pay2Key Ransomware Group Re-Emerges
Cybersecurity

Iran-Linked Pay2Key Ransomware Group Re-Emerges

primereportsBy primereportsMarch 26, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Iran-Linked Pay2Key Ransomware Group Re-Emerges
Share
Facebook Twitter LinkedIn Pinterest Email


Security experts have warned that an Iranian ransomware group has returned with enhanced evasion, execution and anti-forensics capabilities.

Previously linked to Tehran and usually targeting victims aligned with the regime’s interests, Pay2Key has been active since 2020.

However, a new report from Halcyon and Beazley Security warned that “recent US-Iran tensions appear to have accelerated activity from the group.”

The report dissected a new attack on a US healthcare provider which appeared to show an evolving set of TTPs.

Read more on Pay2Key: Suspected Iranian Ransomware Group Targets Israeli Firms

It’s unclear whether the group bought access from an initial access broker or performed reconnaissance on the victim itself. However, with a foothold in the network, the actors used TeamViewer to establish “interactive access” and then began harvesting passwords for lateral movement, using Mimikatz, LaZagne, and ExtPassword.

They then used “Advanced IP Scanner” and ns.exe (presumed to be NetScan) to find hosts and validate credentials, the report explained.

“The threat actors used harvested credentials to pivot across systems, and interacted with Active Directory via dsa.msc, the built-in AD ‘Users and Computers’ console. We believe this was to prevent tooling from automatically flagging the access as anomalous or suspicious,” it continued.

“We believe this was used to identify accounts to be used in concert with ransomware deployment as well as accessing an assortment of backup-related software on victim hosts. Backup systems enumerated include IBackup, Barracuda Yosemite, and Windows Server Backup.”

Ransomware execution was performed through a self-extracting 7zip archive (SFX), abc.exe, which is consistent with previous campaigns. Encryption of the entire infrastructure took just three hours.

The group also deployed a “No Defender” evasion toolkit, which it then removed to hide its tracks.

There was no evidence of data exfiltration, which the report authors claimed “could be due to targeted destruction of evidence by the group.”

Questions Over Iran Links

The attack follows a previous campaign analyzed by Morphisec that coincided with US missile strikes on Iran last year. Since July 2025, the group has received more than $8m in ransom payments linked to 170 victims.

This could indicate that Pay2key remains an Iranian-linked operation whose attacks intensify during periods of geopolitical tension involving the country – but it’s not a given.

“The group’s attempted sale of its entire operation in late 2025, combined with observed ties to Russian-speaking threat actors on criminal forums, raises unresolved questions about the current ownership, operational control and future trajectory of the group’s RaaS platform,” the Halcyon report noted.

Whatever the ownership, however, network defenders should be aware of the threat it poses, the report concluded.

“The group does not always appear to prioritize extortion and financial gain over the destruction of victim environments for strategic impact,” it said.

“Defenders should treat these findings as a clear signal that Pay2Key remains an active, unpredictable, and politically motivated threat whose tactics and objectives warrant ongoing monitoring and proactive intelligence sharing across the security community.”

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleAnthropic Releases The World’s Largest Study On Global AI Attitudes
Next Article The Death of APR as a Metric
primereports
  • Website

Related Posts

Cybersecurity

DOD wants to integrate cyber in all operations, and integrate security into AI

June 3, 2026
Cybersecurity

Trump Signs Order Inviting Voluntary Review of Frontier AI Models

June 3, 2026
Cybersecurity

AI Model Release Tracker: Microsoft AI’s first reasoning model arrives

June 2, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Paxton’s win over Cornyn sets up high-stakes Texas clash with Talarico

May 28, 202616 Views

Global Resources Outlook 2024 | UNEP

December 6, 202510 Views

Texas Democrat Talarico claims voting laws are rigged ahead of Paxton race

May 28, 20269 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Geopolitics
  • Popular Now
  • Artificial Intelligence
  • Cybersecurity
  • Crypto
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • DOD wants to integrate cyber in all operations, and integrate security into AI
  • Bitcoin to slump to new lows after recent sell-off, traders predict
  • House and Senate Appear Closer to Voting to End Trump’s Iran War
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.