confidencehighupdated2026-08-01
Overview
Pay2Key is an Iranian-linked ransomware family attributed to the Fox Kitten APT cluster. It targets Windows environments, encrypts files with ChaCha20, and employs aggressive anti-recovery measures including boot-config tampering, backup deletion, and Hyper-VM destruction.
Capabilities
chacha20-file-encryption
registry-Run-persistence-masquerade
bcdedit-recovery-disable
wbadmin-backup-deletion
shadow-copy-wmi-deletion
hyperv-vm-stop-vhd-dismount
bitlocker-suspension
event-log-clearing-wevtutil
self-erasure-fsutil-setzerodata
lan-share-discovery-netapi
icmp-host-discovery
service-stop-pre-encryption
image-file-execution-options-hijack
Build / RE
- Compiler: MSVC 14.16 (Visual Studio 2017)
- Packing: UPX
- Crypto: ChaCha20 (quarter-round constants visible at
0x408379 in unpacked sample eef5cb41...)
- Libraries: Embeds
markondej/cpp-icmplib for ICMP socket classes
- Resources: RT_RCDATA blob at offset
0xD2BBC (encrypted/compressed)
- Anti-debug:
IsDebuggerPresent
Deploy / ATT&CK
| ID |
Technique |
| T1486 |
Data Encrypted for Impact |
| T1547.001 |
Registry Run Keys / Startup Folder |
| T1490 |
Inhibit System Recovery |
| T1491.001 |
Defacement: Internal Defacement |
| T1070.001 |
Indicator Removal: Clear Windows Event Logs |
| T1070.004 |
File Deletion |
| T1489 |
Service Stop |
| T1083 |
File and Directory Discovery |
| T1135 |
Network Share Discovery |
| T1016 |
System Network Configuration Discovery |
| T1105 |
Ingress Tool Transfer |
Known Samples
| SHA-256 |
Note |
eef5cb41b2c7fe11ce2a0b05de8c6ed583286a0bbc8c632aa073772dcad3efc6 |
UPX-packed, ChaCha20, PAY2KEY_LOG.txt string |
c1a201cf95536c5c9a63f69793515c296e7db0b289328786e8b1cb7a03714b80 |
Unpacked MSVC 14.16, Nov 2025, 4-icon .rsrc, standard sections, identical bootstrap ^[/intel/analyses/c1a201cf95536c5c9a63f69793515c296e7db0b289328786e8b1cb7a03714b80.html] |
References
- VirusTotal:
eef5cb41b2c7fe11ce2a0b05de8c6ed583286a0bbc8c632aa073772dcad3efc6