Ransomware group profile · #229 by claimed victims
Pay2Key ransomware
Pay2Key is ransomware that has been used by the threat actor Fox Kitten. The group seems to operate since July 2020, targetting mainly Israeli companies. Pay2Key has a darknet leak site to public stolen and sensitive information of their victims. Some of their victims: Intel - Habana Labs, IAI - Israel Aerospace Industries, Portnox - Network Security Solutions.
Victimology
Who Pay2Key claims to have breached, from 7 leak-site posts recorded by VULONE.
Claims per month last 12 months
Top sectors
Top countries
Latest claimed victims 7 most recent
| Victim | Sector | Country | Claimed |
|---|---|---|---|
| MT-LAW [Markman&Tomashin Law Firm] | Professional Services | — | 9 Sep 2021 |
| INTER - InterElectric | Energy & Utilities | — | 9 Sep 2021 |
| InfiApps - Joyvoo | Technology | — | 9 Sep 2021 |
| Intel - Habana Labs | Technology | — | 9 Sep 2021 |
| IAI - Israel Aerospace Industries | Manufacturing | — | 9 Sep 2021 |
| Portnox - Network Security Solutions | Technology | — | 9 Sep 2021 |
| Habana Labs | Technology | IL | 13 Dec 2020 |
All 7 Pay2Key victims, searchable
Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.
Tactics, techniques and procedures
ATT&CK technique mapping for Pay2Key is in progress. Victimology, infrastructure status and leak-site tracking are live above.
Indicators, detections and the full playbook
Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.
Frequently asked
Is Pay2Key ransomware still active?
How many victims has Pay2Key claimed?
Which industries does Pay2Key target?
Which countries are most affected by Pay2Key?
Where does VULONE get Pay2Key victim data?
Other ransomware groups
Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].