HomeSecurityFox Kitten: The Iranian hacking group behind Pay2Key ransomware!

Fox Kitten: The Iranian hacking group behind Pay2Key ransomware!

An Iranian APT hacking group called “Fox Kitten” has been linked to the Pay2Key ransomware, which recently began targeting organizations in Israel and Brazil, according to a report by threat intelligence firm ClearSky.

According to the report published on December 17, this campaign is part of the ongoing rivalry between Israel and Iran, with the most recent wave of attacks causing significant damage to some of the companies affected.

Fox Kitten: The Iranian hacking group behind Pay2Key ransomware!

The Iranian-backed hacking group “Fox Kitten” (codenamed Parisite by ICS cybersecurity firm “Dragos”) has been active since at least 2017 and is known for orchestrating and participating in online espionage and data.

Fox Kitten also provides access to compromised corporate networks to another Iranian hacking group, called “APT33,” also known as Elfin and Magnallium. Pay2Key is a relatively new ransomware operation that has targeted Israeli and Brazilian organizations in the past month. Starting in October 2020, Fox Kitten has been using the Pay2Key ransomware in its attacks to steal sensitive and confidential data from industrial, security, and logistics companies. The group has exploited vulnerabilities in Pulse Secure, Fortinet, F5, and Global Protect VPN products or publicly exposed Remote Desktop Protocol (RDP) to gain access to targets’ networks and deploy malware payloads.

According to Check Point, the ability of Pay2Key operators to spread ransomware across a target's entire network within an hour suggests that the hacking group is likely a state-owned enterprise with APT-grade skills and resources.

Fox Kitten: The Iranian hacking group behind Pay2Key ransomware!

The group's hackers also created a rotating device to be used as an outbound proxy server between the infected devices and the command-and-control servers , which helps them avoid or reduce the risk of detection before encrypting all network systems they access.

Indicators of compromise (IoCs) detected during the Pay2Key ransomware attacks also link them to previous devastating Iranian attacks , according to Israeli cybersecurity firms Profero and Security Joes .

Another piece of evidence that Fox Kitten is focused on information theft with Pay2Key is that the group has not even deployed ransomware payloads on the networks of recent victims, but instead only used the stolen data to blackmail the victims.

Fox Kitten: The Iranian hacking group behind Pay2Key ransomware!

Israeli media reported that hackers breached Israeli company Amital earlier this month and then compromised 40 of the company's customers in a supply chain attack.

Additionally, as BleepingComputer reports, the hacking group known as “BlackShadow” is behind a cyberattack that occurred against the Israeli insurance company “Shirbit”, and demanded $1 million to not leak the stolen data.

While the attack that compromised Shirbit's systems is similar to the Pay2Key attacks, it is not yet known whether they are connected, as ClearSky researcher Ohad Zaidenberg reported to BleepingComputer.

Israeli cybersecurity believe these attacks have escalated due to the recent assassination of an Iranian nuclear scientist.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS