📰 Iran-Linked Pay2Key Ransomware Targeted US Healthcare Amidst Military Conflict

🇮🇷 Iran-linked Pay2Key ransomware hit a US healthcare org during recent military conflict. Unusually, no data was stolen, suggesting a disruptive, state-directed motive over financial gain. #Ransomware #Pay2Key #Iran #Healthcare #CyberWarfare

🔗 https://cyber.netsecops.io/articles/iran-linked-pay2key-ransomware-hit-us-healthcare-org-during-conflict/?utm_source=mastodon&utm_medium=social&…

Iran-Linked Pay2Key Ransomware Targeted US Healthcare Amidst Military Conflict

A U.S. healthcare organization was targeted by the Iranian ransomware gang Pay2Key in late February, coinciding with military conflict. The attack suggests a motive beyond financial gain.

CyberNetSec.io

Good day everyone!

Morphisec released an insightful report covering Iranian Cyber Warfare that is targeting the West and other enemies of Iran. The APT involved is #Pay2Key, "an Iranian-backed ransomware-as-as-service (RaaS) operation" that is linked to the Fox Kitten APT group and "closely tied to the well-known #Mimic ransomware."

Normally I call out behaviors and TTPs related but for this report I want to call out the completeness of the report. Not only does it provide more than enough technical details to make actionable in any environment but it also provides a TON of threat intel to support their claims giving the readers and audience an idea if they would be a target or not. It is a great report and I encourage you all to read it! Enjoy and Happy Hunting!

Pay2Key’s Resurgence: Iranian Cyber Warfare Targets the West
https://www.morphisec.com/blog/pay2key-resurgence-iranian-cyber-warfare/

Intel 471 Cyborg Security, Now Part of Intel 471 #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday

Pay2Key’s Resurgence: Iranian Cyber Warfare Targets the West

Pay2Key's recent resurgence is driven by Iranian cyber warfare and targeting western countries. Read the full technical analysis and details.

Morphisec
Iranian group Pay2Key.I2P ramps Up ransomware attacks against Israel and US with incentives for affiliates

An Iranian ransomware group, Pay2Key.I2P, has intensified attacks on U.S. and Israeli targets, offering affiliates higher profits.

Security Affairs
Вымогатели Pay2Key похитили и опубликовали данные дочерней компании Intel #Intel, #Pay2Key https://www.securitylab.ru/news/514803.php https://twitter.com/SecurityLabnews/status/1338501517108797440/photo/1
Вымогатели Pay2Key похитили и опубликовали данные дочерней компании Intel

Злоумышленники предоставили фирме Habana Labs 72 часа, чтобы остановить процесс утечки данных.

Pay2Key et Wannascream : de nouveaux indices confirmeraient que les cyber-attaquants derrière les ransomwares seraient en Iran ! | SOSOrdi.net

SOSOrdi.net
Новый вымогатель Pay2Key способен шифровать сети корпораций всего за час #Pay2Key, #кибератаки https://www.securitylab.ru/news/513872.php https://twitter.com/SecurityLabnews/status/1326070852476088320/photo/1
Новый вымогатель Pay2Key способен шифровать сети корпораций всего за час

Преступники обычно осуществляют атаки после полуночи, когда в компаниях работает меньше IT-сотрудников.