Ransomware · 172 days ago
Iran-linked Pay2Key re-emerged and used Active Directory-focused evasion and credential harvesting to rapidly encrypt a US healthcare provider's infrastructure. Pro‑Ukraine group Bearlyfy escalated attacks on Russian companies and deployed a new GenieLocker strain to demand larger ransoms.
4 sources covering this story
Bearlyfy Hits Russian Firms with Custom GenieLocker Ransomware
Bearlyfy launched 70+ attacks since 2025 using GenieLocker ransomware, targeting Russian firms, driving high ransom payments.
The Record from Recorded Future
Pro-Ukraine hacker group Bearlyfy targets Russian companies with custom ransomware
A pro-Ukrainian hacker group known as Bearlyfy has carried out more than 70 cyberattacks against Russian companies over the past year and is now escalating its campaign with newly developed ransomware tools, researchers have found.
Iran-Linked Pay2Key Ransomware Group Re-Emerges
Halcyon and Beazley Security track the return of Iranian ransomware group Pay2Key
Iran-linked ransomware operation targeted US healthcare provider
The Pay2Key group may have shifted its aims from extortion to destruction.
Part of the PlainSec briefing for 2026-03-29