Pay2Kitten report
ID: c95fd74d-07d6-4ce6-8aeb-6c6f2fbe1b55
STIX ID: report--c95fd74d-07d6-4ce6-8aeb-6c6f2fbe1b55
Threat Score
85/100
Uploaded: 2026-08-15
Published Date: 2020-12-17
Last Modified Date: 2020-12-17
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
## Executive Summary: The report documents the Pay2Key ransomware campaign (June–December 2020) targeting Israeli companies, links the operation to the Iranian APT 'Fox Kitten' with medium-high confidence, and describes exploitation of VPN vulnerabilities (Fortinet, Citrix, F5), use of reverse proxy tools (FRP, Ngrok, LanProxy), lateral movement and persistence techniques, data exfiltration and public leaks (TOR, Keybase, Twitter), detailed IOCs (hashes, IPs, domains) and defensive recommendations.
