Linux Ransomware Pay2Key Targets Enterprise Systems and Cloud Workloads

Linux Ransomware Pay2Key Targets Enterprise Systems and Cloud Workloads

First seen 25 Mar 2026, 21:48 UTC GbhackersCybersecuritynews 86% similarity 58.0

Article Content

Browse articles
ThreatCluster

The Linux ransomware Pay2Key has evolved to target enterprise servers, VMware ESXi hosts, and cloud workloads, indicating a significant shift in its operational focus. Initially recognized for its attacks on Windows systems, particularly against Israeli and Brazilian organizations, it has now expanded its capabilities to Linux environments. The ransomware is attributed to Iranian threat actors and operates as a ransomware-as-a-service (RaaS). Recent reports indicate that this malware is actively exploiting vulnerabilities in organizational infrastructures, raising alarms about its potential impact on enterprise security. The exact number of affected organizations remains unclear, but the scope of its attacks suggests a growing trend in targeting Linux systems. Security professionals are advised to enhance their defenses against this emerging threat. Current mitigation strategies and specific vulnerabilities exploited by Pay2Key have not been detailed in the articles.

Key Points: • Pay2Key ransomware now targets Linux servers and cloud workloads. • The malware is attributed to Iranian threat actors and operates as RaaS. • Organizations must enhance defenses against this evolving ransomware threat.

ThreatCluster AI How this analysis works

Timeline

2026-03-25
Gbhackers and Cybersecuritynews report on Pay2Key targeting Linux systems.
Date unknown
Pay2Key ransomware first detected in the wild.

Community

Browse all →

Tracked Entities in This Story