Recent ransomware wave targeting Israel linked to Iranian threat actors – ZDNet
Two recent ransomware waves that targeted Israeli companies have been traced back to Iranian threat actors, multiple sources have toldZDNettoday.
The ransomware attacks have been taking place since mid-October, have ramped up this month, and have repeatedly focused on Israeli targets.
Israeli companies of all sizes have been targeted by threat actors using thePay2KeyandWannaScreamransomware strains.
Hackers breached corporate networks, stole company data, encrypted files, and asked for huge payouts to deliver a decryption key.
Furthermore, adding to this tactic, this week, the Pay2Key ransomware gang also launched a "leak directory" on the dark web where the group is now leaking data they stole from companies who refused to pay the ransom demand,Ram Levi, Founder and CEO of Konfidas, a cybersecurity consulting firm based in Israel, toldZDNettoday.
The Pay2Key attacks are a curious case because, unlike most other ransomware operations taking place today, these attacks have repeatedly and primarilyfocused on infecting Israeli companies.
Attacks with the WannaScream ransomware have been spotted across the globe, butOmri Segev Moyal, Founder and CEO of Israeli security firm Profero, toldZDNetthat this ransomware is currently available via a Ransomware-as-a-Service (RaaS) model and that one group who rents the ransomware from its creators is targeting Israeli companies in particular.
Profero, who is one of the local security firms that are currently providing Incident Response (IR) services to the many beleaguered Israeli companies, said today it tracked several payments Israeli companies made toExcoino, a cryptocurrency exchange based in Iran.
"The overall sophistication of both the WannaScream and Pay2Key ransomware waves is very average. The low level of sophistication with Pay2Key enabled us to track the bitcoin flow easily," Moyal toldZDNet.
"Our team pinpointed an exit strategy at Excoino, a cryptocurrency exchange based in Iran. This act is very uncommon for major ransomware operators," the Profero exec added.
"An experienced operator will go through mixing services, swapping between different coins via Binance sub-exchanges such as ChangeNow, or other less familiar exchanges such as coin2cards.
"We haven't seen any of those in this case. This might indicate the origin of the attackers, though it can be a false flag as we all aware in our industry."
Profero's findings and the links between Pay2Key and an Iran-based threat actor were also confirmed today by Check Point and a third source who spoke withZDNeton the condition of anonymity.
Check Point, who first spotted the Pay2Key ransomware wave last week, plans to publish an in-depth report on its newest findings and the Iranian links on Thursday.
While payments have not been traced to Excoino for the WannaScream attacks, other indicators in the code and ransom negotiations process have also led Moyal and others to think that this ransomware group is also managed by an Iranian entity.
Moyal's assessment that both Pay2Key and WannaScream are unsophisticated operations was also confirmed by evidence from real-world incidents.
For example, in some early Pay2Key incidents, the ransomware's command-and-control servers didn't release a decryption key to some victims that paid the ransom demand, leaving companies unable to recover their files.
In the case of WannaScream, the ransomware decrypter, the app that victims receive to decrypt their files after paying the ransom demand, has also been throwing errors in some cases, similarly leaving companies unable to recover their data even after making payments.
In recent months, both Israel and Iran have accused each other of carrying out cyber-attacks against each other's critical infrastructure[1,2,3].
At the time of writing, there was no evidence to link either Pay2Key or the WannaScream attacks that have taken place in Israel to an Iranian government entity beyond any doubt. Nonetheless, the door has been left open for future investigations.
More:
Recent ransomware wave targeting Israel linked to Iranian threat actors - ZDNet
- Analysis: Iran is out in the cold as the Mideast unites in support of the Gaza ceasefire - AP News - October 13th, 2025 [October 13th, 2025]
- Analysis: Iran is out in the cold as the Mideast unites in support of the Gaza ceasefire - AP News - October 13th, 2025 [October 13th, 2025]
- Iran says it declined invitation to attend Trump-led Mideast peace summit - - October 13th, 2025 [October 13th, 2025]
- Iran declines invitation to attend summit in Egypt - The Times of Israel - October 13th, 2025 [October 13th, 2025]
- Iran says it's grateful but refuses to engage with counterparts who as it snubs Sisis Gaza peace summit invite - Mint - October 13th, 2025 [October 13th, 2025]
- Iran dismisses possibility of joining Abraham Accords, normalizing ties with Israel - The Times of Israel - October 13th, 2025 [October 13th, 2025]
- Araghchi: We Wont Engage with Those Who Attack and Sanction Iran - WANA News Agency - October 13th, 2025 [October 13th, 2025]
- Irans Economic Collapse Is Fueled by the Regimes Political Choices, Not Sanctions - National Council of Resistance of Iran - NCRI - October 13th, 2025 [October 13th, 2025]
- Iran dismisses Trump's suggestion of normalising ties with Israel as 'wishful thinking' - Reuters - October 13th, 2025 [October 13th, 2025]
- Lindsey Graham Says Keeping 'Iran In A Box' Is Key To Preserving Progress In The Middle East, Trump Ally Warns Tehran Is The 'Common Thread' -... - October 13th, 2025 [October 13th, 2025]
- Air Superiority in the Twenty-First Century: Lessons from Iran and Ukraine - CSIS | Center for Strategic and International Studies - October 13th, 2025 [October 13th, 2025]
- Israel doesnt want war: Iran says Russia relayed Netanyahus message; raises doubt over Gaza ceasefire - The Times of India - October 13th, 2025 [October 13th, 2025]
- Sanctions have limits; Iran is demonstrating that - Tehran Times - October 13th, 2025 [October 13th, 2025]
- Lebanon rejects $60 million Iran aid offer over sanctions fears, envoy says - - October 13th, 2025 [October 13th, 2025]
- Iran says was invited to Gaza summit in Egypt, without confirming attendance - Middle East Eye - October 13th, 2025 [October 13th, 2025]
- The Gendered Dimensions of the Water Crisis in Iran: Impacts on Womens Health, Livelihoods, and Security - NCRI Women Committee - October 13th, 2025 [October 13th, 2025]
- Iran News in Brief October 12, 2025 - National Council of Resistance of Iran - NCRI - October 13th, 2025 [October 13th, 2025]
- Iran says will never join Trump's 'treacherous' Israel normalization deals - - October 13th, 2025 [October 13th, 2025]
- Iran suspends all cooperation with atomic energy watchdog - Azerbaycan24 - October 13th, 2025 [October 13th, 2025]
- Sanctions Shockwave: Treasury Hits Cartels, Iran Oil, And Militia Cash - MyChesCo - October 13th, 2025 [October 13th, 2025]
- FM Araghchi holds telephone conversation with Pakistani counterpart - Islamic Republic of Iran Ministry of Foreign Affairs - October 13th, 2025 [October 13th, 2025]
- Iran saw its entire 'axis of resistance' crumble in two years, says Eugene Kontorovich - yahoo.com - October 13th, 2025 [October 13th, 2025]
- Trump Gives Update on Possible Peace With Iran - Newsweek - October 11th, 2025 [October 11th, 2025]
- Goals and highlights: Russia 2-1 Iran in the international friendly - VAVEL.com - October 11th, 2025 [October 11th, 2025]
- The Iran Challenge Is Big. The Solution Must Be Bigger. - Foreign Policy - October 11th, 2025 [October 11th, 2025]
- New US sanctions target 50 people, companies and ships for allegedly aiding Iran's oil and gas trade - AP News - October 11th, 2025 [October 11th, 2025]
- Iran: 30 Executions on Oct 78, Eve of World Day Against the Death Penalty - National Council of Resistance of Iran - NCRI - October 11th, 2025 [October 11th, 2025]
- Assessing Health Technology Implementation in Iran: A Political Insight - Bioengineer.org - October 11th, 2025 [October 11th, 2025]
- Irans Regime Turns Long-Running Repression into Law With Counter-Infiltration Bill - National Council of Resistance of Iran - NCRI - October 11th, 2025 [October 11th, 2025]
- Its Not Acceptable That Everyone Uses the Strait of Hormuz Except Iran - WANA News Agency - October 11th, 2025 [October 11th, 2025]
- Iran bets on petroleum products for sanctions-busting profits - - October 11th, 2025 [October 11th, 2025]
- Iran Condemns U.S. Military Provocations in the Caribbean and Latin America - WANA News Agency - October 11th, 2025 [October 11th, 2025]
- Over $95 billion in export earnings not returned to Iran, report says - - October 11th, 2025 [October 11th, 2025]
- 5 Christians in Iran to Spend Several Years in Prison for Their Faith - International Christian Concern - October 11th, 2025 [October 11th, 2025]
- Opinion | Snapback Sanctions on Iran Can't Be Allowed to Make Another War Inevitable - Common Dreams - October 11th, 2025 [October 11th, 2025]
- Why Iran Matters: What Every American Needs to Know - CounterPunch.org - October 11th, 2025 [October 11th, 2025]
- 75 years on: Indonesia Iran shared responsibilities and solidarity - Tehran Times - October 11th, 2025 [October 11th, 2025]
- Berlin businesswoman linked to Iran's sanctioned oil trade - ZDF | Iran International - - October 11th, 2025 [October 11th, 2025]
- The iPhonism Fever in Iran: From Selling Kidneys to Taking Heavy Loans for a Bitten Apple - WANA News Agency - October 11th, 2025 [October 11th, 2025]
- China Vows Action Over US Sanctions Tied To Iran Oil Trade - Eurasia Review - October 11th, 2025 [October 11th, 2025]
- IR Iran vs. Russia - October 10, 2025 | Live Scores, Updates, Odds, Injury News and Recaps - Bleacher Report - October 11th, 2025 [October 11th, 2025]
- Iran MP moves to block joining UN terror-financing convention - - October 11th, 2025 [October 11th, 2025]
- IRGC Navy Chief: Iran always protected Strait of Hormuz, never sought its closure - PressTV - October 11th, 2025 [October 11th, 2025]
- Iran has taken care of millions of Afghan refugees with little international support | Letters - The Guardian - October 9th, 2025 [October 9th, 2025]
- Anything Could Happen in Iran - The Atlantic - October 9th, 2025 [October 9th, 2025]
- Iran Divided Over Prospect of New War With Israel - IranWire - October 9th, 2025 [October 9th, 2025]
- Special Report - For Years, Iran Planned a Simultaneous Invasion of Israel Only One Was Carried Out - Alma Research and Education Center - October 9th, 2025 [October 9th, 2025]
- Iran and Trkiyes Managed Geopolitical Rivalry - THE INTERNATIONAL AFFAIRS REVIEW - October 9th, 2025 [October 9th, 2025]
- Irans Budget Theater: How the Regime Uses Public Funds to Preserve Power, Not Serve the People - National Council of Resistance of Iran - NCRI - October 9th, 2025 [October 9th, 2025]
- Israel is trying to drag the US into yet another war, Iran says - Peoples Dispatch - October 9th, 2025 [October 9th, 2025]
- Israel Thwarts Major Weapons Smuggling Attempt From Iran to West Bank Terror Groups - Foundation for Defense of Democracies - October 9th, 2025 [October 9th, 2025]
- Wave of Executions in Iran on the Eve of the World Day Against the Death Penalty - National Council of Resistance of Iran - NCRI - October 9th, 2025 [October 9th, 2025]
- Iran: Rebellious Youth Launch 35 Ops in 19 Cities After Prisoner Executions - National Council of Resistance of Iran - NCRI - October 9th, 2025 [October 9th, 2025]
- Chinese Units of US Chip Firm Sanctioned Over Ties to Iran - Bloomberg.com - October 9th, 2025 [October 9th, 2025]
- Sapped by war and sanctions, Iran seeks Chinese arms as payment for oil | Iran International - - October 9th, 2025 [October 9th, 2025]
- IDF, Shin Bet seize weapons smuggled from Iran to West Bank - Yahoo - October 9th, 2025 [October 9th, 2025]
- China and Russias opposition to snapback is a move against the West, not support for Iran - Tehran Times - October 9th, 2025 [October 9th, 2025]
- Iran to give crushing response to enemies: IRGC Cmdr. - Tehran Times - October 9th, 2025 [October 9th, 2025]
- Sudan at the Crossroads: the QUAD Roadmap, Iran, and the Red Sea Equation - Australian Institute of International Affairs - October 9th, 2025 [October 9th, 2025]
- Iran and Iraqs Bold Plan to Double Tourism: Heres How It Could Transform Your Travel Plans! - Travel And Tour World - October 9th, 2025 [October 9th, 2025]
- Salt storms drive migration as Irans Lake Urmia turns to dust | Iran International - - October 9th, 2025 [October 9th, 2025]
- Kirkus Prize winners include a novel on identity, a history of Iran and an ode to belly buttons - The Independent - October 9th, 2025 [October 9th, 2025]
- Where to watch Iran today? Live soccer streams and TV channels for upcoming games - goal.com - October 9th, 2025 [October 9th, 2025]
- Executions in Iran: A Deadly Record in 2025 - Iran HRM - Iran HRM - October 9th, 2025 [October 9th, 2025]
- Exclusive | How China Secretly Pays Iran for Oil and Avoids U.S. Sanctions - The Wall Street Journal - October 7th, 2025 [October 7th, 2025]
- The complex puzzle of Iran's exit from the FATF black list - Tehran Times - October 7th, 2025 [October 7th, 2025]
- Iran Hits Back After Trumps Threat - newsweek.com - October 7th, 2025 [October 7th, 2025]
- Iran adds 10 trillion cubic feet of gas to its reserves - Reuters - October 7th, 2025 [October 7th, 2025]
- US will 'take to grave' wish to limit Iran's missile range, official says - - October 7th, 2025 [October 7th, 2025]
- 'Iran is developing a nuclear missile to hit the US,' Netanyahu warns in Ben Shapiro interview - The Jerusalem Post - October 7th, 2025 [October 7th, 2025]
- Two years after Oct. 7, an upended Mideast reels from Iran-Israel melee - - October 7th, 2025 [October 7th, 2025]
- When Egypt, Israel and Iran could talk about peace in the Middle East - Dallas News - October 7th, 2025 [October 7th, 2025]
- Iran rejects EU and GCC criticism over nuclear and defense issues - - October 7th, 2025 [October 7th, 2025]
- Pezeshkian Returns From New York to Find Iran More Isolated Than Ever - IranWire - October 7th, 2025 [October 7th, 2025]
- LuminUltra fined $685K by BIS for illegal shipment to Iran - Compliance Week - October 7th, 2025 [October 7th, 2025]
- Iran, Astrakhan expand cooperation in industry, energy, logistics - Tehran Times - October 7th, 2025 [October 7th, 2025]
- Iran and October 7 - PressTV - October 7th, 2025 [October 7th, 2025]
- Islamic Republic of Iran aim to improve in return to the IHF Women's World Championship - IHF - October 7th, 2025 [October 7th, 2025]
- Why Iran is removing four zeroes from its currency: The reason behind the major reform - Times of India - October 7th, 2025 [October 7th, 2025]
- Report: Leaked documents reveal fighter jet deal between Russia and Iran - www.israelhayom.com - October 7th, 2025 [October 7th, 2025]