Emerging Threat Actor Targets Israeli Private Sector with Pay2Key Ransomware
- Actor Motivations: Financial Gain
- Attack Vectors: Backdoor,Ransomware
- Attack Complexity: Medium
- Threat Risk: High Impact/Low Probability
Threat Overview
Check Point Research documents the emergence of Pay2Key, a previously unknown ransomware strain that targeted multiple Israeli corporations in late October and early November 2020. The attacker — believed to be a non-native English speaker and later linked by MITRE to the Fox Kitten threat group — gained initial access through RDP connections, then deployed a custom proxy tool (ConnectPC.exe) on one compromised machine to route all C2 traffic internally, minimizing external network noise. PsExec was used to push the ransomware binary (Cobalt.Client.exe) across the network, achieving full-organization encryption within approximately one hour of initial access. Pay2Key is written in C++ and internally named "Cobalt"; it was under active development at the time of publication, with multiple sample versions compiled within days of each other. The ransomware uses a hybrid AES and RSA encryption scheme, with the RSA public key delivered by the C2 server at runtime — meaning encryption fails if C2 connectivity is unavailable. Each victim received a customized ransom note and encrypted file extension, with demands ranging from 7 to 9 Bitcoin (approximately $110,000–$140,000 at the time). A self-killing mechanism was added in later samples to remove artifacts and reboot the machine post-encryption. Check Point notes the ransomware does not use a packer and was barely detected on VirusTotal at the time of initial analysis, suggesting the actor invested in operational security through proxy design rather than binary obfuscation.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Region | Israel | Verified |
Extracted IOCs
- 4e615861b6d7d778fdc1ac2a61148fe9
- 7db5dd6f2231da6eb07d907312b1abe9
- f3076add8669d1c33cd78b6879e694de
- a048c24ebc42cb3a87dc6d0570ef157cb5479aae
- c3fa78167859ba6c6b39695df0500ebbb6a77881
- eaffd4a8f3c5dfedea3adbcdc06669583d6dc8d0
- 5bae961fec67565fb88c8bcd3841b7090566d8fc12ccb70436b5269456e55c00
- d2b612729d0c106cb5b0434e3d5de1a5dc9d065d276d51a3fb25a08f39e18467
- ea7ed9bb14a7bda590cf3ff81c8c37703a028c4fdb4599b6a283d68fdcb2613f
Tip: 9 related IOCs (0 IP, 0 domain, 0 URL, 0 email, 9 file hash) to this threat have been found.
Overlaps
Source: Swascan - November 2020
Detection (nine cases): 4e615861b6d7d778fdc1ac2a61148fe9, 5bae961fec67565fb88c8bcd3841b7090566d8fc12ccb70436b5269456e55c00, 7db5dd6f2231da6eb07d907312b1abe9, a048c24ebc42cb3a87dc6d0570ef157cb5479aae, c3fa78167859ba6c6b39695df0500ebbb6a77881, d2b612729d0c106cb5b0434e3d5de1a5dc9d065d276d51a3fb25a08f39e18467, ea7ed9bb14a7bda590cf3ff81c8c37703a028c4fdb4599b6a283d68fdcb2613f, eaffd4a8f3c5dfedea3adbcdc06669583d6dc8d0, f3076add8669d1c33cd78b6879e694de
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Frequently Asked Questions: Pay2Key Ransomware Targeting Israeli Companies
A series of targeted ransomware attacks hit multiple Israeli corporations in late October and early November 2020, using a previously unknown strain called Pay2Key. Attackers broke in via RDP, spread the ransomware across entire networks within about an hour, and demanded Bitcoin payments to restore access. Check Point Research identified Pay2Key as a new, custom-built ransomware under active development, and linked the campaign to what MITRE ATT&CK tracks as the Fox Kitten threat group.
The attacker behind Pay2Key remains unidentified by name, but several clues point to an Iranian-linked actor. The ransomware code contains non-native English strings, the attacker created a KeyBase account months before the first attack, and MITRE ATT&CK attributes this activity to Fox Kitten (G0117), an Iranian state-aligned group known for targeting Israeli and other regional organizations. The campaign appears financially motivated, though the relatively modest ransom demands and tight geographic focus on Israel are consistent with a politically oriented operator supplementing state activity.
Pay2Key is a financially motivated ransomware operation. After encrypting a victim's entire network, attackers dropped a customized ransom note demanding 7 to 9 Bitcoin — roughly $110,000 to $140,000 at the time — in exchange for the decryption key. Each note was tailored with the victim organization's name, including custom ASCII art. While the ransom notes mentioned data theft in the style of double-extortion ransomware, Check Point found no evidence that data was actually exfiltrated.
At the time of Check Point's report, multiple large Israeli corporations had been hit within the span of just a few days. The attacks were narrowly focused on the Israeli private sector, though Check Point noted the attacker's TTPs showed no technical barrier to targeting organizations outside Israel. The campaign was notable for its speed — attackers were able to encrypt an entire corporate network within approximately one hour of gaining initial access.
All confirmed victims were Israeli private sector companies across various industries. The source does not identify specific sectors, but describes the targets as "large corporations." The shared characteristic is their Israeli identity and internet-exposed RDP infrastructure, rather than any particular industry vertical.
Attackers connected to a target network via RDP, then deployed ConnectPC.exe on the entry machine to act as an internal proxy — routing all ransomware communications through that single host rather than directly to the attacker's server. This kept outbound network traffic low and hid the true C2 address. PsExec was then used to push the Pay2Key ransomware binary (Cobalt.Client.exe) and a configuration file to every machine in the network. Once running, Pay2Key contacted the C2 server to receive an RSA public key, then encrypted files using a hybrid AES+RSA scheme. After encryption completed, a self-cleanup mechanism removed attacker artifacts and rebooted the machine, leaving a customized ransom note on each system.
Israeli private sector companies represent attractive targets for both financial and geopolitical reasons. From a financial angle, large corporations with operational dependencies are more likely to pay ransoms quickly to restore services. From a geopolitical angle, the attacker's tight focus on Israel — combined with the Fox Kitten attribution — suggests the campaign may serve dual purposes: generating revenue while simultaneously disrupting Israeli business operations as a secondary objective.
The most important step is securing RDP — disable it on internet-facing systems where not needed, and enforce multi-factor authentication and IP allowlisting where it is required. Organizations should monitor for PsExec usage and flag any execution of binaries from C:\Windows\Temp paths across multiple machines in quick succession, which matches Pay2Key's deployment pattern. Because Pay2Key requires a live connection to the attacker's C2 server to deliver the encryption key, blocking unexpected outbound connections from internal hosts may prevent encryption from starting. Use the SHA256 hashes published by Check Point to hunt for Pay2Key artifacts across endpoints.