Cybersecuritynews Linux Ransomware Pay2Key Targets Enterprise Systems and Cloud Workloads
Article Content
- •Pay2Key ransomware now targets Linux servers and cloud workloads.
- •The malware is attributed to Iranian threat actors and operates as RaaS.
- •Organizations must enhance defenses against this evolving ransomware threat.
The Linux ransomware Pay2Key has evolved to target enterprise servers, VMware ESXi hosts, and cloud workloads, indicating a significant shift in its operational focus. Initially recognized for its attacks on Windows systems, particularly against Israeli and Brazilian organizations, it has now expanded its capabilities to Linux environments. The ransomware is attributed to Iranian threat actors and operates as a ransomware-as-a-service (RaaS). Recent reports indicate that this malware is actively exploiting vulnerabilities in organizational infrastructures, raising alarms about its potential impact on enterprise security. The exact number of affected organizations remains unclear, but the scope of its attacks suggests a growing trend in targeting Linux systems. Security professionals are advised to enhance their defenses against this emerging threat. Current mitigation strategies and specific vulnerabilities exploited by Pay2Key have not been detailed in the articles.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Pay2Key in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…