Pay2Key is a ransomware_group tracked by ThreatCluster, appearing in 3 threat clusters built from 5 intelligence report mentions.
Pay2Key is a ransomware_group tracked across 3 threat clusters and 5 intelligence report mentions on ThreatCluster. First observed March 25, 2026; most recent activity April 15, 2026.
In the first quarter of 2026, a significant increase in brute-force authentication attacks was reported, primarily targeting SonicWall and Fortinet FortiGate devices. According to Barracuda, approximately 90% of these…
As of February 12, 2026, organizations worldwide are experiencing an average of 2,090 cyber-attacks per week, largely driven by ransomware incidents. This increase highlights the ongoing challenges faced by businesses…
The Linux ransomware Pay2Key has evolved to target enterprise servers, VMware ESXi hosts, and cloud workloads, indicating a significant shift in its operational focus. Initially recognized for its attacks on Windows…
Pay2Key is a ransomware_group tracked by ThreatCluster, appearing in 3 threat clusters built from 5 intelligence report mentions.
The most recent intelligence report mentioning Pay2Key on ThreatCluster is dated April 15, 2026. Activity was first observed March 25, 2026, giving a tracked span from then to April 15, 2026.
Across ThreatCluster reporting, Pay2Key most frequently co-occurs with Brute Force, Ransomware, Fortinet, Sonicwall, Stryker, among 12 tracked related entities.
The most significant recent cluster is “Surge in Brute-Force Attacks Targeting SonicWall and Fortinet Devices” (4 articles · Updated April 15, 2026). Pay2Key appears across 3 threat clusters in total, listed above with sources.
Pay2Key appears in 5 intelligence report mentions across 3 deduplicated threat clusters, aggregated from 17,000+ monitored sources.