confidencehighupdated2026-08-01

Overview

Pay2Key is an Iranian-linked ransomware family attributed to the Fox Kitten APT cluster. It targets Windows environments, encrypts files with ChaCha20, and employs aggressive anti-recovery measures including boot-config tampering, backup deletion, and Hyper-VM destruction.

Capabilities

  • chacha20-file-encryption
  • registry-Run-persistence-masquerade
  • bcdedit-recovery-disable
  • wbadmin-backup-deletion
  • shadow-copy-wmi-deletion
  • hyperv-vm-stop-vhd-dismount
  • bitlocker-suspension
  • event-log-clearing-wevtutil
  • self-erasure-fsutil-setzerodata
  • lan-share-discovery-netapi
  • icmp-host-discovery
  • service-stop-pre-encryption
  • image-file-execution-options-hijack

Build / RE

  • Compiler: MSVC 14.16 (Visual Studio 2017)
  • Packing: UPX
  • Crypto: ChaCha20 (quarter-round constants visible at 0x408379 in unpacked sample eef5cb41...)
  • Libraries: Embeds markondej/cpp-icmplib for ICMP socket classes
  • Resources: RT_RCDATA blob at offset 0xD2BBC (encrypted/compressed)
  • Anti-debug: IsDebuggerPresent

Deploy / ATT&CK

ID Technique
T1486 Data Encrypted for Impact
T1547.001 Registry Run Keys / Startup Folder
T1490 Inhibit System Recovery
T1491.001 Defacement: Internal Defacement
T1070.001 Indicator Removal: Clear Windows Event Logs
T1070.004 File Deletion
T1489 Service Stop
T1083 File and Directory Discovery
T1135 Network Share Discovery
T1016 System Network Configuration Discovery
T1105 Ingress Tool Transfer

Known Samples

SHA-256 Note
eef5cb41b2c7fe11ce2a0b05de8c6ed583286a0bbc8c632aa073772dcad3efc6 UPX-packed, ChaCha20, PAY2KEY_LOG.txt string
c1a201cf95536c5c9a63f69793515c296e7db0b289328786e8b1cb7a03714b80 Unpacked MSVC 14.16, Nov 2025, 4-icon .rsrc, standard sections, identical bootstrap ^[/intel/analyses/c1a201cf95536c5c9a63f69793515c296e7db0b289328786e8b1cb7a03714b80.html]

References

  • VirusTotal: eef5cb41b2c7fe11ce2a0b05de8c6ed583286a0bbc8c632aa073772dcad3efc6