Payouts King, also known as PayoutsKing and Payouts Kings, is a financially motivated ransomware and data-extortion operation first observed in 2025. It steals sensitive information, selectively encrypts files, and threatens publication through a dedicated leak site. Its targets are concentrated in the United States and Germany, with additional targeting in the United Kingdom, Italy, and Spain. Manufacturing, professional services, technology, and healthcare are prominent victim sectors. Sophos tracks the operation as GOLD ENCOUNTER and STAC4713. Some early-2026 campaigns have been linked to former Black Basta affiliates, but Payouts King is not established as a direct successor to Black Basta. The operation describes itself as not being ransomware-as-a-service. Initial-access methods include SonicWall VPN accounts lacking multifactor authentication, exposed Cisco SSL VPN access, exploitation of SolarWinds Web Help Desk vulnerability CVE-2025-26399, and social engineering. A recurring intrusion pattern combines email bombing with Microsoft Teams calls impersonating internal IT support, followed by persuading victims to grant remote access through Quick Assist. Associated initial access brokers, including UNC6692, supply access for follow-on ransomware activity. Broker-linked campaigns deploy Edgecution, a malicious Microsoft Edge extension that abuses native messaging to communicate with a host-level Python backdoor capable of command execution, file manipulation, and system reconnaissance. Payouts King has concealed attacker tooling in QEMU-hosted Alpine Linux virtual machines to reduce endpoint-security visibility. Later observed intrusions used DLL side-loading to deploy Havoc C2. Post-compromise activity includes network-share and file discovery, theft of directory-service credentials and local credential stores, scheduled-task persistence and privilege elevation, and data exfiltration using Rclone. Its ransomware uses AES-256-CTR with RSA-4096 protection for encryption keys and partially encrypts larger files. Defense-evasion and recovery-inhibition behaviors include runtime string decryption, hashed API resolution, direct system calls to terminate security processes, shadow-copy deletion, and Windows event-log clearing.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
50 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware-related group active since mid-2025 that uses tradecraft associated with former Black Basta affiliates. It was observed using likely AI-assisted, programmatically generated iterations of malicious batch scripts.
The listing associates payoutsking with a purported US victim identified only as M****C, with the masked domain m****.com. The recorded discovery date is 2026-10-04; no breach confirmation, stolen-data details, ransom demand, deadline, or supporting evidence is provided.
Referenced as a user of email-bombing and vishing-style social engineering for initial access.
Claimed a ransomware attack against wireless-infrastructure distributor Tessco LLC, alleging it exfiltrated and encrypted approximately 615 GB of data, including contact information and Salesforce records. These data-volume and record-count claims remain unconfirmed by Tessco.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.