Threats Feed|Unclassified|Last Updated 28/04/2026|AuthorCertfa Radar|Publish Date09/11/2020

Pay2Key Ransomware Attack: Companies in Europe and Israel at Risk

  • Actor Motivations: Financial Gain
  • Attack Vectors: Backdoor,Ransomware
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

Swascan's Cyber Security Research Team conducted first-hand incident response on Pay2Key attacks targeting European companies alongside the simultaneous Israeli campaign documented by Check Point Research. Swascan was one of the first teams to identify the ransomware, submitting Cobalt.Client.exe to VirusTotal on October 27, 2020 — the same day as the first confirmed attacks. Forensic investigation revealed that initial access occurred as early as October 20, 2020, with attackers entering via an exposed vulnerable service and using RDP to connect to compromised devices. From there, PsExec (PSEXESVC.exe) was used to distribute the ransomware across the network. Swascan also identified Ngrok, hidden as dllhost.exe in Windows event logs, as a likely backdoor tool the attackers used to maintain persistent remote access to infected infrastructure. ConnectPC.exe was recovered from crash logs and confirmed as the internal proxy used to relay C2 communications. Ransom demands ranged from $100,000 to $200,000 in Bitcoin depending on company size and the number of compromised devices — a higher ceiling than reported by Check Point. Full-network encryption completed in approximately three hours, with the active encryption phase taking roughly one hour. Only two antivirus engines flagged the sample on initial VirusTotal submission, indicating very low detection at time of deployment. Note: the original source URL is no longer accessible (404); this analysis is based on the archived PDF attachment.

Detected Targets

TypeDescriptionConfidence
RegionIsrael
Verified
RegionEuropean Countries
Verified

Extracted IOCs

  • 4e615861b6d7d778fdc1ac2a61148fe9
  • 7db5dd6f2231da6eb07d907312b1abe9
  • f3076add8669d1c33cd78b6879e694de
  • a048c24ebc42cb3a87dc6d0570ef157cb5479aae
  • c3fa78167859ba6c6b39695df0500ebbb6a77881
  • eaffd4a8f3c5dfedea3adbcdc06669583d6dc8d0
  • 5bae961fec67565fb88c8bcd3841b7090566d8fc12ccb70436b5269456e55c00
  • d2b612729d0c106cb5b0434e3d5de1a5dc9d065d276d51a3fb25a08f39e18467
  • ea7ed9bb14a7bda590cf3ff81c8c37703a028c4fdb4599b6a283d68fdcb2613f
download

Tip: 9 related IOCs (0 IP, 0 domain, 0 URL, 0 email, 9 file hash) to this threat have been found.

Overlaps

UnclassifiedEmerging Threat Actor Targets Israeli Private Sector with Pay2Key Ransomware

Source: Check Point - November 2020

Detection (nine cases): 4e615861b6d7d778fdc1ac2a61148fe9, 5bae961fec67565fb88c8bcd3841b7090566d8fc12ccb70436b5269456e55c00, 7db5dd6f2231da6eb07d907312b1abe9, a048c24ebc42cb3a87dc6d0570ef157cb5479aae, c3fa78167859ba6c6b39695df0500ebbb6a77881, d2b612729d0c106cb5b0434e3d5de1a5dc9d065d276d51a3fb25a08f39e18467, ea7ed9bb14a7bda590cf3ff81c8c37703a028c4fdb4599b6a283d68fdcb2613f, eaffd4a8f3c5dfedea3adbcdc06669583d6dc8d0, f3076add8669d1c33cd78b6879e694de

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Frequently Asked Questions: Pay2Key Ransomware Attacks on European and Israeli Companies

Pay2Key is a custom ransomware strain that targeted companies in both Europe and Israel in late October 2020. Attackers broke into networks through internet-exposed services, spread the ransomware across entire organizations using standard IT tools, and demanded Bitcoin payments to restore access. Swascan's security team was among the first to respond to incidents and document the malware, while Check Point Research simultaneously covered attacks on Israeli companies. The campaign represents an early example of rapid, targeted ransomware operations against specific geographic regions.

The attacker's identity remains unconfirmed, though several indicators point toward an Iranian-linked actor. The ransomware's internal code contains non-native English strings, the Pay2Key Keybase account was created months before the attacks began, and MITRE ATT&CK links this activity to Fox Kitten (G0117), an Iranian state-aligned group with a history of targeting Israeli organizations. The campaign appears financially motivated, though its tight focus on Israel and Europe may also serve geopolitical objectives.

Pay2Key is a financially motivated ransomware operation. After encrypting victims' files, attackers demanded between $100,000 and $200,000 in Bitcoin — scaled to the company's size and the number of devices compromised. Each victim received a customized ransom note with their organization's name. While the ransom notes mentioned data theft, Swascan and Check Point found no concrete evidence that data was actually exfiltrated.

The campaign hit companies across Europe and Israel simultaneously, with Swascan responding to European incidents and Check Point covering Israeli targets. Multiple large corporations were affected within days of each other. The attacker's infrastructure suggests pre-operational access dating to October 20, 2020 — a week before the first publicly reported attacks. The speed of the campaign was notable: full-network encryption completed in roughly three hours after the ransomware was deployed.

Confirmed victims were private sector companies across Europe and Israel. Neither Swascan nor Check Point identify specific industries, describing targets broadly as companies and corporations. The common factor appears to be internet-facing infrastructure with exposed RDP or vulnerable services, rather than any particular sector or size threshold — though the ransom scaling by company size and device count suggests the attacker sought out larger organizations.

Attackers first accessed a victim's network via an exposed internet-facing service, then used RDP to connect directly to machines. They deployed ConnectPC.exe as an internal proxy to route all ransomware communications through a single compromised host, hiding the true C2 server. PsExec spread Cobalt.Client.exe across the network. Swascan's forensic investigation also found Ngrok hidden as dllhost.exe — likely installed as a persistent backdoor for ongoing access independent of the ransomware. Once the ransomware ran, it contacted the C2 for an RSA key, encrypted files using AES+RSA, and removed itself after completion. Full-network encryption finished in approximately three hours.

European and Israeli companies with internet-exposed infrastructure are attractive targets for financially motivated attackers seeking large ransom payouts. The attacker scaled demands by company size, suggesting deliberate targeting of organizations large enough to pay six-figure ransoms quickly to restore operations. For an Iranian-linked actor like Fox Kitten, Israeli targets may also carry geopolitical value beyond the financial return.

Disable or tightly restrict internet-facing RDP — it was the confirmed entry point across all known victims. Hunt specifically for Ngrok disguised as dllhost.exe in non-standard paths, as this backdoor may persist on systems even after the ransomware has been removed and cleaned up. Block outbound connections to Ngrok infrastructure from corporate endpoints. Monitor for PsExec execution and Cobalt.Client.exe artifacts using the SHA256 hashes published by Swascan and Check Point. Pay2Key requires a live C2 connection to deliver its encryption key, so isolating affected hosts from outbound internet access can prevent encryption from completing.