New Pay2Key ransomware encrypts networks within one hour

[correlate]

Level 18
Thread author
Top Poster
Well-known
May 4, 2019
801
A new ransomware called Pay2Key has been targeting organizations from Israel and Brazil, encrypting their networks within an hour in targeted attacks still under investigation.

Michael Gillespie, the creator of ID Ransomware, has also seen submissions from Pay2Key victims predominantly from Brazilian IP addresses.
Although used in attacks against multiple Brazilian entities, this ransomware is not related to yesterday's RansomExx attacks targeting Brazil's government networks.
 

[correlate]

Level 18
Thread author
Top Poster
Well-known
May 4, 2019
801
Introduction
Last weekend we issued a ransomware alert about a wave of attacks using a never-seen-before strain dubbed ‘Pay2Key.’ Our investigation suggested the ransomware operators were mostly targeting Israeli companies. The ransomware used in the attacks spread rapidly across victims’ networks, leaving significant parts of the network encrypted along with a ransom note, threatening to leak stolen corporate data unless the ransom is paid.

As more and more reports on Pay2Key attacks have accumulated, we started seeing victims paying the ransom because they were unwilling to take the risk of finding their sensitive corporate data being posted online. However, this unfortunate situation also created an opportunity to understand who is behind this new ransomware.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top