◇ SIGN IN
← all actors
ransomware

Pay2Key (Fox Kitten / Pioneer Kitten, Iran-linked)

activemedium confidence
Ransomware
Pay2Key.I2PFox KittenPioneer KittenParisiteUNC757RUBIDIUMLemon Sandstorm
Attribution
nation-state-linked (Iran-nexus; assessed link to Fox Kitten / Pioneer Kitten)
Origin
Iran
First seen
2020
Last active
2025
Motivation
Hacktivism / ransomware (ideologically driven, Iran-nexus)
Confidence
medium
MENA targeting
Israel, UAE, Azerbaijan
Sectors
Cross-sector; ideologically motivated vs. Israel/US, financial secondary
MITRE ATT&CK

Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.

Why it mattersRansomware actor, medium confidence, documented targeting Israel, UAE, Azerbaijan (Cross-sector; ideologically motivated vs. Israel/US, financial secondary sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

Pay2Key is an Iran-linked ransomware and extortion brand originally seen in 2020 against Israeli targets and reassessed as a tool of the Iran-nexus group Fox Kitten (Pioneer Kitten); it re-emerged in 2025 as 'Pay2Key.I2P' offering affiliates outsized profit shares for attacking Israel and the US.

History

Pay2Key first appeared in late 2020 in a wave of intrusions against Israeli companies, characterized less by extortion revenue than by public shaming and disruption, which analysts (notably ClearSky) tied to Iranian interests via the 'Pay2Kitten' assessment. MITRE ATT&CK tracks the broader actor set as Fox Kitten (G0117), an Iran-nexus group active since at least 2017 known for exploiting internet-facing appliances (VPNs, firewalls), deploying web shells, and providing initial access that has been linked to multiple ransomware operations.

In 2025 the brand resurfaced as 'Pay2Key.I2P,' hosting infrastructure on the anonymous I2P network rather than Tor and operating as a ransomware-as-a-service program. Reporting indicates it was promoted on Russian and Chinese darknet forums and on X, added a Linux payload variant in mid-2025, and offered affiliates an elevated cut (reported around 70-80%) specifically for participating in attacks against Iran's adversaries, blending financial and ideological motives.

Its targeting is heavily oriented toward Israel and the United States, with MENA-relevant claims including Israel, the UAE and Azerbaijan. Public reporting cited multi-million-dollar cumulative proceeds and dozens of payouts within months of the 2025 relaunch. As with all extortion brands, individual victim claims should be treated as unverified unless confirmed by a reputable source; the Iran-nexus attribution is an analytic assessment supported by multiple vendors rather than an admission.

Notable campaigns

2020
Original Pay2Key campaign vs Israel
Ransomware/extortion wave against Israeli firms assessed by ClearSky as Iran-linked ('Pay2Kitten').
2025
Pay2Key.I2P relaunch
Re-emerged as an I2P-hosted RaaS offering up to ~80% affiliate share for attacks on Israel and the US; claimed multi-million-dollar proceeds.

Claimed victims · 7 tracked

Leak-site postings via ransomware.live — claimed by the group, not confirmed breaches. Metadata only. MENA Ransomware Watch →

DateVictimCountrySector
MT-LAW [Markman&Tomashin Law Firm]Professional Services
INTER - InterElectricEnergy & Utilities
InfiApps - JoyvooTechnology
Intel - Habana LabsTechnology
IAI - Israel Aerospace IndustriesManufacturing
Portnox - Network Security SolutionsTechnology
Habana LabsIsraelTechnology