Malware.View on attack.mitre.org
Pay2Key is a ransomware written in C++ that has been used by Fox Kitten since at least July 2020 including campaigns against Israeli companies. Pay2Key has been incorporated with a leak site to display stolen sensitive information to further pressure victims into payment.
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
Pay2Key can identify the IP and MAC addresses of the compromised host. |
| T1070.004 File Deletion |
Pay2Key can remove its log file from disk. |
| T1082 System Information Discovery |
Pay2Key has the ability to gather the hostname of the victim machine. |
| T1090.001 Internal Proxy |
Pay2Key has designated machines in the compromised network to serve as reverse proxy pivot points to channel communications with C2. |
| T1095 Non-Application Layer Protocol |
Pay2Key has sent its public key to the C2 server over TCP. |
| T1486 Data Encrypted for Impact |
Pay2Key can encrypt data on victim's machines using RSA and AES algorithms in order to extort a ransom payment for decryption. |
| T1489 Service Stop |
Pay2Key can stop the MS SQL service at the end of the encryption process to release files locked by the service. |
| T1573.002 Asymmetric Cryptography |
Pay2Key has used RSA encrypted communications with C2. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.