Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Pay2Key

168
Global rank
198 infographic chevron month
Month rank
197 infographic chevron week
Week rank
0
IOCs

Pay2Key is a ransomware strain primarily written in C++ for Windows (with recent Linux variants), attributed to Iranian-linked actors, notably the Fox Kitten APT group (also known as UNC757 or related operations). First observed in late 2020, it employs double-extortion tactics (encrypting files and threatening to leak stolen data) while showing signs of both financial and state-aligned motivations. It has resurfaced in campaigns targeting Western organizations, including rapid encryption attacks on healthcare.

Ransomware
Type
Unknown
Origin
1 October, 2020
First seen
24 June, 2026
Last seen

How to analyze Pay2Key with ANY.RUN

Type
Unknown
Origin
1 October, 2020
First seen
24 June, 2026
Last seen

IOCs

IP addresses
48.209.138.168
20.190.160.20
48.209.6.48
135.233.95.144
135.233.95.135
23.59.18.102
172.211.123.249
23.52.181.141
48.192.1.64
2.16.204.142
172.211.123.248
40.126.53.18
2.16.164.106
2.16.164.9
95.100.102.101
172.178.240.162
172.211.123.250
57.153.246.3
20.190.160.128
2.22.114.96
Hashes
df3f619804a92fdb4057192dc43dd748ea778adc52bc498ce80524c014b81119
67401342192babc27e62d4c1e0940409cc3f2bd28f77399e71d245eae8d3f63c
81970dbe581373d14fbd451ac4b3f96e5f69b79645f1ee1ca715cff3af0bf20d
d7446e2f307027c9bda2a92d1df1c13c376581372f6ae8708f4d5baccb2e6813
cd2c00ce027687ce4a8bdc967f26a8ab82f651c9becd703658ba282ec49702bd
682ada4732a0d9282ba25b65c17d5c487dea484a95e04e5c50e5c3fb2550f0f6
9bd6dbc93cb0eaf8628d176f2e92a47de39d1e76ff89d71e20a0adfcde91cef0
51eca3cfc0917f0cb8b439ae7bf55525924a9e12083a078d8c9422b1b0b2ce47
1d4b776dbc96f90f4ebcbef4e9e71c1e4543af3df862954d53b8e5a8e4c722eb
b8ae6364c0e09631e8585ecc9ccbd18fc4a34aa5e46c3c5f7b9b94d0b02470a4
6b2ce84c384134c13bcdbf03f3163ebd9b59e6e40d5a881df02a2b671f8f12a1
13ceaf1e781db57fcdcbc30882763fcce095edcc99af0afcb2d2b227183a85ba
81fad4c1d3bb7678fcd32b29dcf113b4ab869653c4a31edef61ec560cfd1d5b5
16de9e9b70d7972b3a23116ea4d32e3e6f289a2b1516b5d8ce66883680ccf6fd
751a1de9926bc71ec3e88a2433e14bdd2cec9dd7bab7068ab3574dc1ea87792c
f57c54809c6f56867d167bfcf4763d6a4abe4e27fdb9c4421cefd6fcfa68cf1e
c9fb39828a6523088facf944e2da8bb2844d902c23bf37cbd9a855b316e507d6
ae570eee41a8fbdedbdae7154fcad136b401a9d43aa8d3a80684d6fca9bcfe5b
0b4db7a09ee3306e969fe0b32228422f223eb2f71bd5d1ec1a0d9ef16b405c58
82b9db18853a960a88dc865714229eeb57979339be6c49ddecfda0766eec9d4b
Domains
slscr.update.microsoft.com
www.microsoft.com
crl.microsoft.com
www.bing.com
fe3cr.delivery.mp.microsoft.com
self.events.data.microsoft.com
login.live.com
watson.events.data.microsoft.com
client.wns.windows.com
activation-v2.sls.microsoft.com
google.com
nexusrules.officeapps.live.com
settings-win.data.microsoft.com
go.microsoft.com
licensing.mp.microsoft.com
oneocsp.microsoft.com
ocsp.digicert.com
clientservices.googleapis.com
edgedl.me.gvt1.com
www.google.com
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?processorclockspeed=3094&flightids=&updateoffereddays=4294967295&branchreadinesslevel=cb&oemmanufacturername=dell&isclouddomainjoined=0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&sku=48&activationchannel=retail&attrdataver=186&ismdmenrolled=0&processorcores=6&processormodel=amd%20ryzen%205%203500%206-core%20processor&totalphysicalram=6144&primarydisktype=4294967295&flightingbranchname=&chassistypeid=1&oemmodelnumber=dell&systemvolumetotalcapacity=260281&sampleid=95271487&deviceclass=windows.desktop&app=muse&disabledualscan=0&appver=10.0&oemsubmodel=j5cr&locale=en-us&isalwaysonalwaysconnectedcapable=0&ms=0&defaultuserregion=244&updateserviceurl=http%3a%2f%2fneverupdatewindows10.com&osver=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&deferqualityupdateperiodindays=0&ring=retail&deferfeatureupdateperiodindays=30
https://settings-win.data.microsoft.com/settings/v3.0/onesettings/client?osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&localdeviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&attrdataver=186&osuilocale=en-us&osskuid=48&app=wosc&appver=&isflightingenabled=0&telemetrylevel=1&devicefamily=windows.desktop
https://activation-v2.sls.microsoft.com/slactivateproduct/slactivateproduct.asmx?configextension=retail
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://login.live.com/rst2.srf
https://login.live.com/ppsecure/deviceaddcredential.srf
https://slscr.update.microsoft.com/sls/%7b522d76a4-93e1-47f8-b8ce-07c937ad1a1e%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
http://www.microsoft.com/pkiops/crl/microsoft%20update%20signing%20ca%202.3.crl
http://crl.microsoft.com/pki/crl/products/microoceraut_2010-06-23.crl
http://www.microsoft.com/pkiops/crl/microsoft%20time-stamp%20pca%202010(1).crl
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20product%20root%20certificate%20authority%202018.crl
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20signing%20ca%202.3.crl
http://www.microsoft.com/pkiops/crl/microsoft%20update%20signing%20ca%202.2.crl
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20signing%20ca%202.2.crl
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
https://slscr.update.microsoft.com/sls/ping
https://slscr.update.microsoft.com/sls/%7be7a50285-d08d-499d-9ff8-180fdc2332bc%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
http://www.microsoft.com/pkiops/crl/microsoft%20update%20signing%20ca%202.1.crl
Last Seen at

Recent blog posts

post image
Intelligence-Driven SOC: Modernizing Threat M...
watchers 10509
comments 0
post image
Supply Chain Security: How ANY.RUN Helps US a...
watchers 5759
comments 0
post image
Smile, You're on Camera. Part 2: Hiring Lazar...
watchers 44045
comments 0

Pay2Key Explained: From Israeli Extortion Campaign to Global Ransomware-as-a-Service Threat

Key Takeaways

  • Pay2Key is a targeted ransomware family that combines encryption with credential theft, lateral movement, and data exfiltration.

  • The malware has been linked by multiple researchers to Iranian threat activity targeting organizations rather than individual users.

  • Attackers commonly gain initial access using compromised VPN accounts, exposed remote services, or stolen enterprise credentials.

  • Enterprise-wide compromise often occurs long before ransomware deployment through reconnaissance and privilege escalation.

  • Strong identity protection, network segmentation, MFA, and tested offline backups significantly reduce ransomware risk.

  • Continuous monitoring for credential abuse and lateral movement can reveal Pay2Key activity before encryption begins.

  • ANY.RUN Threat Intelligence Lookup and Threat Intelligence Feeds help security teams proactively identify Pay2Key infrastructure, detect related indicators of compromise, enrich SIEM and EDR telemetry, and stop attacks during the early stages of intrusion.

threatName:"pay2key"

Pay2Key sample analyses in ANY.RUN Sandbox Pay2Key sample analyses in ANY.RUN Sandbox found via TI Lookup

What is Pay2Key Malware?

Pay2Key is a ransomware family that emerged in late 2020 and quickly gained attention for targeting Israeli organizations and businesses through carefully planned intrusions. Unlike commodity ransomware, Pay2Key operators combined ransomware deployment with credential theft, lateral movement, and data exfiltration, allowing them to maximize operational disruption and extortion pressure. The malware has also been linked by multiple security researchers to Iranian state-sponsored threat activity, making it notable as an example of financially motivated attacks overlapping with geopolitical objectives.

It encrypts files on compromised systems using strong cryptographic algorithms before demanding cryptocurrency payments in exchange for a decryption key.

While its technical capabilities resemble those of many enterprise ransomware families, Pay2Key distinguished itself through its operational approach. Rather than relying solely on automated infections, its operators typically gained privileged access to corporate networks, moved laterally across environments, harvested credentials, and selectively deployed ransomware where it would cause the greatest disruption.

Several cybersecurity vendors have assessed with moderate to high confidence that the Pay2Key campaign was operated by an Iranian threat group commonly tracked as Fox Kitten (UNC757/APT35-associated infrastructure), although the ransomware itself appeared to pursue financial extortion alongside broader strategic objectives.

The malware often formed the final stage of a larger intrusion involving:

  • initial compromise
  • privilege escalation
  • credential theft
  • reconnaissance
  • lateral movement
  • selective encryption
  • ransom negotiations

This multi-stage approach makes Pay2Key significantly more dangerous than opportunistic ransomware that simply encrypts a single endpoint.

View Pay2Key sample analysis in ANY.RUN Sandbox

Pay2Key attack exposed in Interactive Sandbox Pay2Key attack exposed in Interactive Sandbox

How Pay2Key Threatens Businesses and Organizations

Pay2Key's dual identity — cybercriminal RaaS and state-aligned disruption tool — makes it a broader risk than a typical for-profit ransomware family:

  • Operational shutdown. The Linux variant runs with root privileges, disables SELinux and AppArmor, kills competing processes, and selectively encrypts mounted filesystems — directly hitting database servers, application backends, and virtual machine hosts that many businesses cannot operate without.
  • Extortion without the usual playbook. Some recent intrusions showed no data exfiltration at all, a departure from standard double-extortion ransomware. This suggests some attacks aim at disruption and reputational damage rather than a clean financial transaction, making "just pay the ransom" a less reliable path to recovery.
  • Amplified reach through affiliates. The RaaS model, with its unusually high payout share, actively recruits outside operators, increasing the volume and unpredictability of attacks beyond what a single state-run team could carry out.
  • Fast lateral spread. Historical incidents show Pay2Key operators moving from initial foothold to network-wide encryption in about an hour once inside, leaving little time for manual containment.
  • Geopolitical targeting logic. Because affiliates are incentivized to hit "enemies of Iran," organizations in Israel and the U.S. — or with visible ties to either — carry elevated risk independent of their perceived security maturity.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Victimology: Who Is Most at Risk?

Pay2Key's targeting has evolved alongside its operators' goals, but several patterns stand out:

  • Israeli enterprises — the original 2020 campaign concentrated on Israeli corporations, with ClearSky research pointing to defense, energy, insurance, and logistics organizations as primary targets, often used as a cover for intelligence collection alongside the ransomware deployment.
  • U.S. organizations, including healthcare — Pay2Key.I2P's 2025–2026 campaigns explicitly courted affiliates to attack American targets, and a confirmed 2026 intrusion hit a U.S. healthcare provider, a sector where downtime carries life-safety consequences and strong pressure to resolve incidents quickly.
  • Critical infrastructure and government-adjacent sectors — Fox Kitten's broader operational history includes government, defense, telecommunications, oil and gas, and aviation organizations, largely reached through exposed remote-access infrastructure rather than sector-specific phishing.
  • Any organization running exposed Linux servers, virtualization hosts, or cloud workloads — the 2025 Linux encryptor specifically targets the infrastructure layer (databases, app backends, VM hosts) that underpins cloud and hybrid environments, regardless of industry.
  • Organizations with unpatched edge devices — because initial access relies heavily on known VPN and firewall vulnerabilities, any business running Citrix, Pulse Secure/Ivanti, F5 BIG-IP, Fortinet, Palo Alto GlobalProtect, or Check Point gateways without current patches is a candidate victim, independent of size or sector.

The Evolution of Pay2Key and Notable Activity

  • June–October 2020 – Fox Kitten operators register infrastructure and compile the first Pay2Key samples; ransom notes demand relatively modest sums of 7–9 BTC (roughly $110K–$140K at the time).

  • Late 2020 – Wave of attacks against Israeli companies, largely via compromised RDP access following earlier VPN exploitation. Victim data is leaked on a Tor-hosted site, publicly tagging victims and media outlets — behavior researchers characterized as psychological/information warfare rather than pure extortion.

  • 2021–2024 – Fox Kitten continues broad VPN-exploitation campaigns (Pulse Secure, Citrix, F5, Fortinet, Palo Alto) across government, defense, and energy sectors; a 2024 joint CISA/FBI advisory describes the group brokering network access to ransomware crews including NoEscape, RansomHouse, and BlackCat/ALPHV.

  • February 2025 – Relaunch as Pay2Key.I2P on a Russian-language underground forum, offering a flat $20,000 payout per successful attack and, later, an affiliate profit share increased to 80% for attacks supporting Iranian interests.

  • June 2025 – Release of a Linux-compatible encryptor, extending the malware from endpoints to servers, virtualization platforms, and cloud infrastructure.

  • Mid-2025 – Operators claim over 50 successful ransom payments and more than $4 million collected in four months, with individual affiliates reportedly earning up to $100,000.

  • Late 2025 – Pay2Key's operation is listed for sale on dark web forums and the group's own account; the sale process concludes without clear public resolution.

  • February 2026 – Confirmed intrusion at a U.S. healthcare organization, analyzed jointly by Beazley Security and Halcyon, showing a more evasive, forensically aware variant with no observed data exfiltration — a break from the group's earlier double-extortion pattern.

How Pay2Key Gets Into Systems and Spreads

Consistent with Fox Kitten's long-standing tradecraft, Pay2Key rarely relies on phishing as its primary entry point. Instead:

  • 1. Initial access via public-facing infrastructure. Operators scan the internet — reportedly using Shodan — for unpatched, internet-facing VPN and networking appliances, historically including Citrix NetScaler/ADC (CVE-2019-19781, CVE-2023-3519), Pulse Secure/Ivanti Connect Secure (CVE-2019-11510, CVE-2024-21887), F5 BIG-IP (CVE-2020-5902, CVE-2022-1388), Fortinet FortiOS (CVE-2018-13379), Palo Alto GlobalProtect (CVE-2024-3400), and Check Point Security Gateways (CVE-2024-24919).

  • 2. Credential and webshell foothold. After exploitation, operators plant webshells, harvest credentials, and create discreetly named local or domain accounts (e.g., disguised as service accounts) to blend into legitimate administrative activity.

  • 3. Internal pivoting. Exposed or brute-forced RDP is used as a secondary access route and as the primary mechanism for moving laterally across the network once inside.

  • 4. Command-and-control and tunneling. The group routes traffic through reverse proxy tools such as FRPC and ReverseSocks5 to funnel activity through a single internet-connected pivot host, minimizing its external footprint; the newer Pay2Key.I2P infrastructure adds I2P-based anonymized C2 to the mix.

  • 5. Rapid deployment. Once positioned, operators have historically distributed the ransomware payload across an entire compromised network within about an hour, using native tools like PsExec and PowerShell rather than custom deployment infrastructure — which helps the activity blend into normal admin traffic until encryption begins.

How Pay2Key Malware Functions

Upon execution (often as Cobalt.Client.exe), it reads a config file, generates RSA keys, and communicates with C2 (via proxy). It receives a dynamic configuration (target extensions, ransom note customized per victim, .pay2key or similar extension).

The malware discovers systems, stops interfering services (e.g., MS SQL), encrypts files (full/partial modes in Linux with ChaCha20; RSA+AES in Windows), and drops customized ransom notes. It includes self-cleanup, persistence mechanisms, and system info gathering. Linux builds require root, disable protections, and target mounts/backups.

View the attack chain in ANY.RUN Interactive Sandbox:

Pay2Key detonated in Interactive Sandbox Pay2Key sample detonated in Interactive Sandbox

Pay2Key ransomware extracts several component files into the temporary directory, including data.bin and a command script named setup.cmd, which is later executed by Command Prompt.

Pay2Key components and scripts

Pay2Key components and scripts Pay2Key components and processes

The setup.cmd script contains the following logic:

The script first determines whether the system is running under WOW64 and launches the appropriate PowerShell executable. It then removes previously extracted files, checks for the presence of additional payload components, and extracts multiple password-protected archives using 7za.exe. During execution, it reconstructs the 7-Zip executable from an embedded payload and uses it to unpack the remaining components.

If data2.bin is present, the script extracts files into the Avast installation directory (C:\Program Files\Avast Software\Avast) and executes additional utilities from there.

Malicious script behavior Malicious script behavior

If data4.bin exists, it extracts and executes task.ps1, which performs additional malicious actions. The script then extracts data3.bin and launches sfx-i386-amd64.exe, waiting for its execution to complete before continuing.

The PowerShell code embedded in the script also contains a custom XOR-based decoding routine used to decrypt embedded payloads stored in files such as data.bin, data1.bin, and data5.bin. The decoded payloads are executed directly in memory, while data1.bin is decoded and written to disk as 7za.exe.

Pay2Key decoded payload Pay2Key decoded payload

After extracting and launching all required components, the ransomware executes Everything.exe, which is used to rapidly enumerate files across the system before encryption.

Pay2Key mutex Pay2Key mutex

Before encrypting files, the malware performs several defense evasion actions. It suspends BitLocker protection using:

powershell.exe -ExecutionPolicy Bypass "Get-BitLockerVolume | Suspend-BitLocker"

It also disables hibernation using:

powercfg.exe -H off

Additionally, the ransomware uses delayed execution through the following command:

Pay2Key delayed execution command Pay2Key delayed execution command

This introduces a short delay before disabling security software and removing the extracted Avast directory.

Finally, the ransomware encrypts victim files by appending the .randomchars_p2key extension and drops the ransom note as:

C:\temp\HowToRestoreFiles.txt

Pay2Key ransom note Pay2Key ransom note

…instead of placing it in the standard Windows temporary directory.

How Businesses Can Use ANY.RUN’s Threat Intelligence Solutions Against Pay2Key

Because Pay2Key's initial access almost always runs through exploited edge infrastructure rather than user-clicked payloads, defense has to start before the encryptor ever executes — and that means having visibility into the exploitation and staging activity, not just the ransomware binary.

ANY.RUN's Threat Intelligence Lookup gives SOC and DFIR teams a way to move from an isolated indicator to full attack context in seconds. If your team spots a suspicious IP, file hash, mutex, or command line potentially tied to Fox Kitten or Pay2Key activity, TI Lookup lets you search across dozens of event parameters — file paths, registry keys, network indicators, YARA rules — and pivot directly into the underlying interactive sandbox sessions where those indicators appeared.

That's especially valuable for a threat actor like Fox Kitten, whose tooling (webshells, proxy utilities, PsExec-based lateral movement) is often reused across intrusions; a single confirmed indicator can surface related infrastructure and TTPs from other victims' sessions before your own incident escalates.

ANY.RUN's Threat Intelligence Feeds take the opposite but complementary approach: instead of searching reactively, they push a continuously updated stream of malicious IPs, domains, and URLs — sourced from millions of real-world sandbox detonations — directly into your SIEM, firewall, or SOAR. For a group that rotates C2 infrastructure and proxy pivots as often as Fox Kitten does, fresh, low-false-positive feeds help block newly stood-up infrastructure before it's used against you, rather than relying solely on signatures for the ransomware binary itself.

Used together, TI Feeds shrink the window of exposure to known-bad infrastructure automatically, while TI Lookup gives analysts the investigative depth to confirm, scope, and hunt for related activity once something suspicious surfaces.

Beyond threat intelligence, organizations should treat these as baseline controls against Pay2Key specifically:

  • Patch edge devices on an accelerated cycle. Citrix, Ivanti/Pulse Secure, F5, Fortinet, Palo Alto, and Check Point appliances are Fox Kitten's primary entry point — patch lag is the vulnerability the group is actually exploiting.
  • Restrict and monitor RDP. Disable direct internet exposure of RDP, enforce MFA on remote access, and alert on anomalous RDP session patterns.
  • Harden Linux hosts. Enforce SELinux/AppArmor in enforcing mode where possible, monitor for unauthorized changes to their state, and audit cron jobs regularly for unexpected entries.
  • Segment critical infrastructure. Isolate database servers, virtualization hosts, and backup systems from general user network segments to limit the blast radius of a compromised foothold.
  • Maintain tested, offline backups. Given evidence that some Pay2Key intrusions skip data theft and go straight to disruption, backup integrity and recovery speed matter as much as prevention.
  • Detonate suspicious samples in an interactive sandbox before trusting artifacts recovered from incident response, to confirm behavior and extract fresh IOCs for the rest of the environment.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Pay2Key demonstrates that modern ransomware attacks are rarely isolated encryption events. Instead, they are the culmination of carefully orchestrated intrusions involving stolen credentials, reconnaissance, lateral movement, and data theft.

Although Pay2Key itself has remained relatively limited in scale compared to larger ransomware families, the tactics employed by its operators mirror those used by today's most sophisticated ransomware groups. Organizations that focus only on detecting file encryption risk missing the earlier stages where attackers are far easier to stop.

By combining proactive threat intelligence, continuous monitoring, strong identity security, and layered defenses, businesses can identify Pay2Key-related activity before it escalates into a costly ransomware incident.

Trial TI Lookup to start gathering actionable threat intelligence on the malware that threatens your business sector and region: just sign up to ANY.RUN.

HAVE A LOOK AT

Qilin Ransomware screenshot
Qilin ransomware (predecessor known as “Agenda”) is a rapidly evolving ransomware-as-a-service (RaaS) operation targeting organizations worldwide. Known for double extortion tactics (encrypting files while also threatening to leak stolen data) Qilin has quickly gained notoriety for its customization, flexibility, and impact on critical infrastructure.
Read More
Crypto malware screenshot
Crypto malware
miner xmrig jsminer
Crypto mining malware is a resource-intensive threat that infiltrates computers with the purpose of mining cryptocurrencies. This type of threat can be deployed either on an infected machine or a compromised website. In both cases the miner will utilize the computing power of the device and its network bandwidth.
Read More
SnappyClient screenshot
SnappyClient is a sophisticated C++-based command-and-control (C2) implant first identified in December 2025. Delivered primarily via the modular HijackLoader, it functions as a versatile remote access tool with strong information-stealing capabilities, particularly focused on cryptocurrency wallets, browser data, and system control. It employs advanced evasion techniques, encrypted communications, and modular configurations to maintain persistence and evade detection.
Read More
BlindEagle screenshot
BlindEagle
blindeagle
BlindEagle is a cyber threat actor primarily associated with espionage and credential theft campaigns targeting organizations in Latin America, especially Colombia. Active since at least 2018, the group relies heavily on phishing, remote access trojans (RATs), PowerShell scripts, and social engineering to infiltrate systems and maintain persistence. BlindEagle is known for continuously evolving its delivery mechanisms and malware stack to bypass detection and compromise high-value targets.
Read More
Oyster screenshot
Oyster
oyster
Oyster (also seen in reporting as Broomstick or CleanUpLoader) is a Windows backdoor/loader actively used in multi-stage intrusion campaigns. Recent campaigns weaponize SEO-poisoning and malvertising to trick IT and dev users into downloading trojanized installers (PuTTY, WinSCP, Microsoft Teams, etc.), which then drop Oyster to establish a persistent foothold and load additional payloads (often leading to data theft or ransomware).
Read More
Cephalus screenshot
Cephalus
cephalus
Cephalus is a targeted ransomware threat discovered in 2025. It’s known for infiltrating organizations that deal with sensitive data through compromised RDP access. It leverages DLL sideloading with a legitimate SentinelOne executable. Cephalus is able to exfiltrate data and destroy backup options. Its payload is also tailored to each victim, which makes identification and mitigation more complex.
Read More