Open Nav
Sign Up

Defending against the “Pay2key” cyber campaign

Ben Brauner

December 16, 2020

Cyber Incident Response

Pay2key – December 2020

Over the last 10 days, OP Innovate has handled a number of cyber incidents resulting from the Iranian ‘Pay2key’ campaign. This intelligence gathering and ransomware campaign has targeted over 80 Israeli organizations thus far, and if successful, would have paralyzed significant sectors of the Israeli industry.

Incident Response Methodology

An incident response methodology coalesces is a number of procedures which aim to identify, investigate, handle and then learn from security incidents. The methodology seeks to minimize impact and downtime, bring about rapid recovery, and feed into an iterative feedback loop which strives to decrease future recurrence. 

The commonly accepted incident response phases are:

This document focuses on the detection, containment and eradication of the “Pay2key” cyber campaign.

Go to the Windows Task Scheduler and identify the newly created task named “VerifiedPublisherCertStoreVerify”. It appears in the \Microsoft\Windows\AppID directory and replaces the existing legitimate Windows task of the similar name (VerifiedPublisherCertStoreCheck) (figure 1).

Figure 1: Task Scheduler showing the disabled legitimate task and its persistent malicious replacement

Investigation of the malicious task shows that it runs an application masquerading as a Windows application each day at 9am. The name of this application is sccm.exe, and mimics the Windows System Center Configuration Manager (SCCM). Use of a legitimate Windows application name may help the malware file to evade some antivirus software which looks for unknown file names. 

This malware file is located in the c:\windows\speech folder. Its location is a further effort to evade the AV software (figure 2).

Figure 2: Malware location

Eradication action items: 

  • The malicious scheduled task must be deleted.
  • The malware file found in c:\windows\speech\sccm.exe must be deleted.

A further artifact found was the creation of a local administrative user on the server, the account named “DefaultAccounts$” (figures 3 and 4). This seeks to mimic the “DefaultAccount”, also known as the Default System Managed Account (DSMA), a built-in account introduced in Windows 10 version 1607 and Windows Server 2016. It remains present in Windows 10, Windows Server 2016 and Windows Server 2019. The legitimate DefaultAccount user is absent since the server predates Windows Server 2016.

Figure 3: The newly created DefaultAccounts$ account

Eradication action items: 

  • The DefaultAccounts$ user must be deleted

Further recommendations to mitigate the attack:

  • Block all traffic to and from the following IPs: 63.32.140.129 , 13.81.213.207 , 162.223.91.13 
  • Reset passwords for all domain admin users, VPN users. Enable and enforce 2FA.
  • Make sure your VPN software and firewall firmware are up to date

Attack Kill Chain

If you find the the indicators of compromise (IOCs) or experience any other suspicious activity please do not hesitate to contact us: 

 

OP Innovate Ltd. © 2020 

   www.op-c.net | info@op-c.net 

Resources highlights

Two Citrix NetScaler RCE Zero-Days Exploited in the Wild: CVE-2026-88771 & CVE-2026-88772

Two critical zero-day vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway are being actively exploited to compromise vulnerable appliances. Tracked as CVE-2026-88771 and CVE-2026-88772, both…

Read more >

citrix netscaler_cve-2026-88771-88772

Critical cPanel Flaw CVE-2026-87899 Enables Root Code Execution

A critical vulnerability in cPanel & WHM can allow an authenticated cPanel user to escalate privileges and execute arbitrary code as the root user, potentially…

Read more >

cpanel_cve-2026-87899

WordPress Click2Shell Chains Forced Theme Installation to Remote Code Execution

A newly disclosed WordPress vulnerability chain dubbed Click2Shell can allow an unauthenticated attacker to turn a single malicious link opened by a logged-in WordPress administrator…

Read more >

wordpress click2shell

Cisco ISE Zero-Day CVE-2026-76460 Exploited for Authentication Bypass and Root Access

Cisco has disclosed a maximum-severity vulnerability in Cisco Identity Services Engine (ISE) that is being actively exploited in the wild. Tracked as CVE-2026-76460, the vulnerability…

Read more >

cisco ise_cve-2026-76460

Critical Check Point VPN RCE Flaws CVE-2026-85102 and CVE-2026-85103 Face Imminent Exploitation Risk

Check Point has released security updates for two critical vulnerabilities affecting its VPN infrastructure that could allow unauthenticated remote attackers to execute arbitrary code on…

Read more >

check point_cve-2026-85102-cve-2026-85103

SonicWall SMA1000 Zero-Days CVE-2026-83548 and CVE-2026-83549 Exploited for Unauthenticated RCE

SonicWall has disclosed two actively exploited zero-day vulnerabilities affecting its SMA1000 secure remote access appliances. The vulnerabilities, tracked as CVE-2026-83548 and CVE-2026-83549, affect the SMA1000…

Read more >

sonicwall sma1000_cve-2026-83548-83549
Under Cyber Attack?

Fill out the form and we will contact you immediately.