Israeli Cybersecurity Giant Tracks Ransom Payments From New Cyber Attack To Iranian Nationals
Error: Contact form not found.
by Meir Orbach / CTech

A symbol of the cryptocurrency Bitcoin. Photo: Pixabay.
CTech – Israeli cybersecurity giant Check Point Software Technologies revealed a new type of ransomware, dubbed Pay2Key, that has footprints leading to Iran. The attackers have already succeeded in harming several Israeli companies, including a leading law firm and a tech company in the gaming industry. Data on the attacked companies has already made its way to the dark web, with the attackers demanding 7-9 Bitcoin in ransom (approximately $110,000-$149,000). It is important to note that this is a new type of ransomware, different from the type that was recently used to attack Tower and Sapiens.
Check Point experts determined that the hack was carried out through employees’ remote connection system. “This is a fast and sophisticated type of ransomware that encrypts entire organizational networks within an hour, while threatening to leak large amounts of data belonging to the targeted organizations to the darknet if the ransom isn’t paid,” read a company statement.
Check Point said that in at least three instances the hackers indeed leaked the data of the attacked organizations. Most of the ransomware victims, at least a dozen, are Israeli companies of various sizes.
According to the investigation carried out at Check Point’s labs, four Israeli victims of the Pay2Key attacks have decided to pay the ransom, which enabled its experts to track the payment transfers between crypto wallets. In cooperation with WhiteStream, an Israeli blockchain intelligence company, the researchers were able to follow the Bitcoin money route and found that they all ended up in what appeared to be an Iranian cryptocurrency exchange named Excoino.
According to Check Point, Excoino is an Iranian company that provides secure cryptocurrency transactions services for Iranian citizens, with registration requiring users to have a valid Iranian phone number and ID. Based on the transfer route, the researchers were able to determine that the people behind the ransomware attacks were Iranian nationals.
Hormuz to Stay Closed Unless US Meets Iran’s Conditions, Iran Official Says
Russia Says Syria Base Deal Will Boost Ties, Source Says Some Russian Forces Will Stay
Rising UK Antisemitism Leaves Jewish School Principals Forced to Focus on Security, Not Education, Study Finds
US Rep. Ro Khanna Struggles to Defend ‘Genocide’ Accusations Against Israel
Israel Sees Major New Diplomatic Gains in Latin America
Mamdani’s Recent Video Is a Masterclass in Distorting What’s Happening in Israel and the Middle East
Former Hamas Hostage Sagui Dekel-Chen Performs Album Written During Captivity
Was Israel’s War With Iran a Success? The Answer Is Still Unclear
The Jewish History of Prague (PART ONE)
Why American Charedim Are Watching Israel’s Elections Closely





US Rep. Ro Khanna Struggles to Defend ‘Genocide’ Accusations Against Israel
Israel Sees Major New Diplomatic Gains in Latin America
Mamdani’s Recent Video Is a Masterclass in Distorting What’s Happening in Israel and the Middle East
The Jewish History of Prague (PART ONE)
Why American Charedim Are Watching Israel’s Elections Closely



