Back to blog

Blog Post

Pay2Key Ransomware Gang Resurfaces with Geopolitical Focus

Share on social

Jul 18, 2025

Lorem ipsum

Table of contents

Share on social

Join the newsletter
Pay2Key Ransomware Gang Resurfaces with Geopolitical Focus

[Pay2Key Ransomware Return]

In this blog series we spotlight one of the stories from our cybersecurity newsletter, Beacon.

The Pay2Key ransomware-as-a-Service (RaaS) gang, previously linked to the Iranian nation-state threat group Fox Kitten (UNC757), has re-emerged with a sharpened geopolitical focus and a revamped affiliate model aimed squarely at Western organizations.

According to new research, the group’s latest activity suggests it is now a more dangerous and ideological driven threat actor, particularly in light of recent Iran-Israel-US tensions.

First identified in 2020, Pay2Key gained popularity through campaigns against Israeli targets. Despite remaining relatively obscure compared to bigger ransomware names, the gang has been on the radar of US federal agencies due to its connections to Iranian state-backed operations.

Now, researchers have confirmed that Pay2Key has resurfaced with a new ransomware variant, called Pay2Key.I2P, which is targeting organizations in the west. The ransomware gang has introduced more incentives for affiliates, offering up to 80 percent of ransom payments for attacks directed at the “enemies of Iran,” including Israel and the US.

“Their focus on Western targets, coupled with rhetoric tied to Iran's geopolitical stance, positions this campaign as a tool of cyber warfare," the researchers wrote.

The ransomware gang has also introduced a Linux-targeted build of its ransomware, expanding its ability to attack a wider variety of IT environments. "The addition of a Linux-targeted ransomware build in June 2025 further expands their attack surface, threatening diverse systems."

While profit-sharing models of 80% or more are not unprecedented with groups like BlackCat and DragonForce offering similar deals, researchers emphasize that Pay2Key’s ideological motivation sets them apart.

"Personal communications reveal a group driven by ideology, rewriting their tools to maximize impact," the researchers wrote. "As geopolitical tensions fuel such threats, proactive defense is essential."

Lizzie Clark
LC

Author

Lizzie Clark

Marketing Executive at Searchlight Cyber

Lizzie is an experienced IT and cybersecurity marketing professional with six years of specialist experience in the industry. Lizzie produces a range of content - from blogs and long-form articles to newsletters and social media - with a focus on writing that informs and engages technical audiences.

Related Blog Posts

August 13, 2026

Phishing and Takedown now managed entirely in Monitor

August 6, 2026

How to Measure Preemptive Threat Exposure Management (PTEM) Success

August 5, 2026

August 4th – This Week’s Top Cybersecurity and Dark Web Stories

July 31, 2026

How Does Preemptive Threat Exposure Management Improve Exposure Prioritization?

July 29, 2026

July 28th – This Week’s Top Cybersecurity and Dark Web Stories

July 24, 2026

Preemptive Threat Exposure Management: Frequently Asked Questions

Never miss a beat

Get all news and updates about Searchlight Cyber, directly in your inbox.

Subscribe
Please enter a valid email address.
Background Gradient