Ransomware & Extortion · Ransomware

Pay2Key Re-emerges; Bearlyfy Escalates Ransomware Campaign

Iran-linked Pay2Key re-emerged and used Active Directory-focused evasion and credential harvesting to rapidly encrypt a US healthcare provider's infrastructure. Pro‑Ukraine group Bearlyfy escalated attacks on Russian companies and deployed a new GenieLocker strain to demand larger ransoms.

4 sources · Mar 27

Timeline

Sources

Part of the PlainSec briefing for 2026-03-29

Every edition of this story: Pay2Key Re-emerges; Bearlyfy Escalates Ransomware Campaign