Israeli Cybersecurity Giant Tracks Ransom Payments From New Cyber Attack To Iranian Nationals
Error: Contact form not found.
by Meir Orbach / CTech

A symbol of the cryptocurrency Bitcoin. Photo: Pixabay.
CTech – Israeli cybersecurity giant Check Point Software Technologies revealed a new type of ransomware, dubbed Pay2Key, that has footprints leading to Iran. The attackers have already succeeded in harming several Israeli companies, including a leading law firm and a tech company in the gaming industry. Data on the attacked companies has already made its way to the dark web, with the attackers demanding 7-9 Bitcoin in ransom (approximately $110,000-$149,000). It is important to note that this is a new type of ransomware, different from the type that was recently used to attack Tower and Sapiens.
Check Point experts determined that the hack was carried out through employees’ remote connection system. “This is a fast and sophisticated type of ransomware that encrypts entire organizational networks within an hour, while threatening to leak large amounts of data belonging to the targeted organizations to the darknet if the ransom isn’t paid,” read a company statement.
Check Point said that in at least three instances the hackers indeed leaked the data of the attacked organizations. Most of the ransomware victims, at least a dozen, are Israeli companies of various sizes.
According to the investigation carried out at Check Point’s labs, four Israeli victims of the Pay2Key attacks have decided to pay the ransom, which enabled its experts to track the payment transfers between crypto wallets. In cooperation with WhiteStream, an Israeli blockchain intelligence company, the researchers were able to follow the Bitcoin money route and found that they all ended up in what appeared to be an Iranian cryptocurrency exchange named Excoino.
According to Check Point, Excoino is an Iranian company that provides secure cryptocurrency transactions services for Iranian citizens, with registration requiring users to have a valid Iranian phone number and ID. Based on the transfer route, the researchers were able to determine that the people behind the ransomware attacks were Iranian nationals.
Canada Sees Record Surge in Antisemitic Incidents for Second Consecutive Year, New Report Finds
Smith College to Hold Talks With Students for Justice in Palestine Following Unauthorized Encampment
Jewish Groups Blast Mamdani for Vetoing Bill to Limit Protests Near Schools
Hezbollah Embeds Terror Apparatus in Lebanon’s Health System
Cruz Calls for US to Join Israel, Taiwan in Recognizing Somaliland
‘Scarier Than the Holocaust’: Survivor of Nazi Camps, Oct. 7 Dies at 92
Slovenia, Ireland, Spain Refuse to Air Eurovision Song Contest Over Israel’s Inclusion
Organizer of Kanye West’s Portugal Concert Confirms Scheduled Show After String of Canceled Performances
Mediators Still Seek to Bridge US, Iran Gaps Despite No Face-to-Face Talks
Five Stand Trial in Germany Over Attack on Israeli Defense Company Office





When a Jewish Icon Moves to Israel for Her Safety: A Warning Sign for the Netherlands
Palestinian Authority: Jesus Was a Muslim Palestinian Terrorist
Cruz Calls for US to Join Israel, Taiwan in Recognizing Somaliland
India and Israel Have the Same Response to Terrorism: Why Is Only One Treated Differently?
Bahrain Revokes Citizenship of 69 People for ‘Glorifying or Sympathizing With’ Iranian Attacks



