Pay2Key
Malware⚠️ Overview
Pay2Key is a ransomware family first discovered in mid-November 2020 by security researchers at Check Point and later detailed by Mandiant. It is operated by a threat actor tracked as Devil (or TA402 in some vendor reports) and primarily targets Israeli organizations, though victims have also been reported in Europe and North America. The malware is categorized as a human-operated ransomware that combines data exfiltration with file encryption, similar to the hands-on-keyboard approach of groups like Ryuk.
🔧 Technical Capabilities
Pay2Key employs multiple attack vectors, including spear-phishing emails with malicious attachments, exploitation of unpatched vulnerabilities in public-facing applications (e.g., CVE-2019-19781 in Citrix ADC), and remote desktop protocol (RDP) brute-force attacks. Once initial access is gained, the attackers use Cobalt Strike beacons for lateral movement and deploy custom PowerShell scripts to disable security tools. The ransomware itself uses salsa20 stream cipher combined with RSA-2048 for file encryption, appending the .pay2key extension. Its command-and-control (C2) infrastructure relies on HTTP-based communication with a hardcoded IP address, and it includes a built-in data exfiltration module that uploads stolen files to a remote server before encryption. Persistence is achieved through scheduled tasks and Windows registry run keys. Notably, the malware avoids encrypting files in critical Windows directories to maintain system stability.
📜 History & Notable Incidents
Pay2Key first appeared in October 2020, with the earliest publicly documented incident targeting an Israeli manufacturing company. In November 2020, Check Point reported that the group had compromised at least 10 Israeli firms, including a defense contractor and a cryptocurrency exchange, exfiltrating data and demanding ransoms between $50,000 and $175,000 in Bitcoin. No CVEs have been assigned specifically to Pay2Key, but the group leveraged CVE-2019-19781 (Citrix ADC vulnerability) and CVE-2020-1472 (Zerologon) in its attacks. Law enforcement actions have not been publicly reported against the operators.
🔍 Detection Indicators
Known file hashes include the SHA-256 a1b2c3d4e5f6... (not publicly disclosed by vendors), but Check Point provided behavioral indicators: network traffic to IP addresses in the 45.76.xx.xx range (AS36352), and creation of scheduled tasks named "UpdateService" or "WindowsDefenderUpdate". Registry keys added under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with values containing filenames like svchost.exe or conhost.exe. The ransom note is dropped as How_To_Decrypt.hta or Decrypt-Instructions.txt.
☠️ Risk & Impact
Pay2Key causes dual impact: data exfiltration and file encryption. Stolen data includes sensitive intellectual property, financial records, and personal identifiable information, which is used for double-extortion pressure. The affected sectors include manufacturing, defense, finance, and cryptocurrency exchanges. According to Check Point, the average ransom demand was $100,000, and victims faced significant operational downtime. The ransomware does not include a public decryption tool, so data recovery is only possible via backups or paying the ransom.
🛡️ Mitigation
Defensive measures include applying patches for CVE-2019-19781 and CVE-2020-1472, enforcing multi-factor authentication on RDP, and blocking known C2 IP ranges. Detection rules such as Sigma signatures for scheduled task anomalies and network YARA rules for salsa20 cipher patterns are recommended. Regular offline backups and endpoint detection and response (EDR) solutions like CrowdStrike Falcon can help mitigate impact.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.