[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fNgUxOdwYxFRekWSLJ6xPUlhvyMZ5NJlOpR8iQf6EXrA":3},{"article":4,"iocs":38,"watch_terms":43},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":18,"category":19,"article_tags":22},"9fb7ae0d-4f0e-46c0-a368-a34e66bf727d","Iran Deploys 'Pseudo-Ransomware,' Revives Pay2Key Operations","iran-deploys-pseudo-ransomware-revives-pay2key-operations","Iranian APTs are blurring the lines between state-sponsored and cybercriminal activities to target high-impact US organizations.","Iranian state-sponsored actors have resumed Pay2Key operations, deploying what researchers term 'pseudo-ransomware'—malware designed to extort victims while blurring attribution between state and criminal activity. The campaign targets high-impact US organizations, demonstrating Iran's continued evolution of hybrid attack tactics that combine espionage, extortion, and geopolitical leverage.","Iranian APTs deploy pseudo-ransomware targeting US orgs via revived Pay2Key operations.",null,"https:\u002F\u002Fwww.darkreading.com\u002Fthreat-intelligence\u002Firan-pseudo-ransomware-pay2key-operations","https:\u002F\u002Feu-images.contentstack.com\u002Fv3\u002Fassets\u002Fblt6d90778a997de1cd\u002Fbltea953d17d8a9625a\u002F69cb9dbb871fcd599c9b5bc4\u002Fmuhammadtoqeer-iran-cyber-flag-shutterstock.jpg?width=1280&auto=webp&quality=80&disable=upscale","2026-03-31T13:31:33+00:00","2026-03-31T18:00:25.825244+00:00",8,[],"6cbdd207-aaa1-4176-9534-e156b125e917",{"id":18,"icon":11,"name":20,"slug":21},"Nation-state","nation-state",[23,28,33],{"category":24},{"id":25,"icon":11,"name":26,"slug":27},"2e06f76c-d5b9-4f54-9eef-4d3447b10730","Breaches","breaches",{"category":29},{"id":30,"icon":11,"name":31,"slug":32},"7d8b5ab8-ea0b-4ced-ae97-ec251b86993a","Ransomware","ransomware",{"category":34},{"id":35,"icon":11,"name":36,"slug":37},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[39],{"type":40,"value":41,"context":42},"malware","Pay2Key","Iranian APT pseudo-ransomware used in extortion campaigns targeting US organizations",[]]