Pay2Key
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Pay2Key is a ransomware operation that emerged in late 2020 and has been linked to a series of attacks against Israeli businesses. Israeli cybersecurity firms Check Point and Profero identified Pay2Key as a relatively new ransomware operation responsible for multiple incidents in November 2020, including the compromise of Habana Labs, an Israeli AI processor developer owned by Intel. Profero has publicly stated that it believes Iranian threat actors are behind the Pay2Key operation after tracing the group’s ransom‑payment wallets to Iranian bitcoin exchanges, a claim also echoed in media reports that described the activity as a suspected Iranian cyber campaign targeting Israeli companies. A separate threat actor known as BlackShadow was identified as the perpetrator of a ransomware‑style leak against the Israeli insurance company Shirbit; while the tactics resemble those of Pay2Key, any direct connection between the two groups remains unspecified in the source material.
The tactics associated with Pay2Key include the deployment of the Pay2Key ransomware strain, the exfiltration of sensitive data such as Windows domain account information, DNS zone information, and file listings from Gerrit code‑review systems, and the subsequent publication of that data on a leak site accompanied by threats such as a “72‑hour deadline to stop leaking process.” Initial access in several incidents appears to have been gained through a supply‑chain vector: threat actors compromised the Israeli shipping and cargo software company Amital and then used that foothold to infiltrate approximately forty of Amital’s client networks. Security analysts from Profero and the Israeli firm Security Joes have observed overlapping indicators of compromise between the Amital‑supply‑chain incidents and earlier Pay2Key attacks, suggesting a reuse of tools or infrastructure. The ransomware operation has been described by observers as not being primarily financially motivated but rather intended to cause disruption to Israeli interests, a characterization that appears in the reporting on the Habana Labs incident.
Notable publicly reported operations attributed to this activity include the November 2020 breach of Habana Labs, which resulted in the leakage of internal documents and source‑code images; the Amital‑related supply‑chain intrusion that affected dozens of Israeli logistics firms; and the Shirbit incident attributed to BlackShadow, which exhibited similar data‑leak tactics although any linkage to Pay2Key remains unconfirmed. Additionally, media outlets have reported suspected Iranian cyber intrusions targeting Israel Aerospace Industries and other Israeli firms, with analysts describing those events as likely Iranian‑origin campaigns. These incidents collectively illustrate a pattern of cyber operations directed at Israeli entities that involve ransomware deployment, data theft and public leakage, supply‑chain compromise, and suspected Iranian sponsorship, as documented in the cited sources.
Incidents
Attributed incidents are available to members.
3 incidents