R
Ransomwhere.org
Live MapLatest VictimsGroups
PaymentsTTPsIdentifyNewsDataAPI
LIVE
Ransomwhere.org

Real-time ransomware intelligence platform. Tracking threat actors, victims, and payments to raise awareness and help defend against ransomware attacks worldwide.

Platform

  • Live Map
  • Latest Victims
  • Groups
  • Payments
  • Identify
  • News

Resources

  • Data & Methodology
  • API Docs
  • NoMoreRansom
  • Ransomware.live
  • CISA Advisories

Data sourced from Ransomware.live API. For informational purposes only.

© 2026 Ransomwhere.org

Groups/pay2key

pay2key

Inactive

Pay2Key is ransomware that has been used by the threat actor Fox Kitten. The group seems to operate since July 2020, targetting mainly Israeli companies. Pay2Key has a darknet leak site to public stolen and sensitive information of their victims. Some of their victims: Intel - Habana Labs, IAI - Israel Aerospace Industries, Portnox - Network Security Solutions.

7
Victims
1
Sites

Known Leak Sites

pay2key2zkg7arp3kv3cuugdaqwuesifnbofun4j6yjdw5ry7zw2asid.onionDLS

Victims (7)

Live
MT-LAW [Markman&Tomashin Law Firm]
pay2key
INTER - InterElectric
pay2key
InfiApps - Joyvoo
pay2key
Intel - Habana Labs
pay2key
IAI - Israel Aerospace Industries
pay2key
Portnox - Network Security Solutions
pay2key
Habana Labs
pay2keyIL

Top Targeted Countries

Unknown6
Israel1

Profile

:

Activity

Total victims7
Countries affected2
Last seen