Iran-Backed Pay2Key Ransomware Makes a Comeback with Increased 80% Profit Incentive for Cybercriminals
Jul 11, 2025
Cyber Warfare / Cybercrime
The Iranian-backed ransomware-as-a-service (RaaS), Pay2Key, has reemerged amid the escalating Israel-Iran-U.S. conflict, now offering larger financial rewards to cybercriminals targeting Israel and the U.S. Operating under the new name Pay2Key.I2P, this scheme is believed to be associated with the hacking group known as Fox Kitten (also referred to as Lemon Sandstorm). According to Morphisec security researcher Ilia Kulmin, “Pay2Key.I2P appears to be affiliated with the notorious Fox Kitten APT group and shares capabilities with the well-known Mimic ransomware.” The group has officially raised its profit share for affiliates supporting Iran or conducting attacks against its adversaries to 80%, up from 70%, highlighting their ideological motivations. Last year, the U.S. government identified the advanced persistent threat’s (APT) strategy of executing ransomware attacks through covert partnerships.