logo

Pay2Kitten report

ID: c95fd74d-07d6-4ce6-8aeb-6c6f2fbe1b55

STIX ID: report--c95fd74d-07d6-4ce6-8aeb-6c6f2fbe1b55

Threat Score

85/100

Uploaded: 2026-08-15

Published Date: 2020-12-17

Last Modified Date: 2020-12-17

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
## Executive Summary: The report documents the Pay2Key ransomware campaign (June–December 2020) targeting Israeli companies, links the operation to the Iranian APT 'Fox Kitten' with medium-high confidence, and describes exploitation of VPN vulnerabilities (Fortinet, Citrix, F5), use of reverse proxy tools (FRP, Ngrok, LanProxy), lateral movement and persistence techniques, data exfiltration and public leaks (TOR, Keybase, Twitter), detailed IOCs (hashes, IPs, domains) and defensive recommendations.