Payouts King is an emerging ransomware and extortion group first observed in 2025 and assessed with high confidence to include or work closely with former BlackBasta affiliates. The group has been linked to the GOLD ENCOUNTER activity cluster and has shown tradecraft overlap with BlackBasta-era intrusion patterns, particularly spam bombing, Microsoft Teams impersonation of internal IT staff, vishing, and abuse of Quick Assist to obtain hands-on remote access. Payouts King has also been associated with an initial access broker ecosystem, including activity tied to UNC6692, which has delivered the Edgecution malware to establish footholds later sold for ransomware deployment. The group conducts double-extortion operations, stealing data before selectively encrypting files and pressuring victims through a leak site. Publicly reported victimology indicates targeting of manufacturing, healthcare, information technology, and defense-related supply-chain organizations, with victims observed in the United States, Germany, and Poland. Reported cases and broader ransomware tracking place much of its activity in North America and Europe. Payouts King has demonstrated advanced defense-evasion and post-compromise tradecraft. Researchers have linked it to abuse of QEMU to deploy hidden Alpine Linux virtual machines on compromised hosts, enabling covert tooling, reverse SSH-style backdoor access, credential theft, reconnaissance, and reduced visibility to host-based security products. Associated intrusions have also used scheduled tasks for persistence and SYSTEM-level execution, data exfiltration tooling, and in some cases DLL sideloading to launch command-and-control frameworks. Its Windows ransomware payload uses strong hybrid cryptography, including RSA-4096 and AES-256-CTR, and supports intermittent encryption for larger files to accelerate impact. Analysis has identified extensive anti-analysis measures such as runtime string decryption, hashed API resolution, custom checksum-based obfuscation, direct system calls to evade EDR hooks, conditional execution controls, and deliberate cleanup actions including deletion of shadow copies, clearing of event logs, and recycle-bin emptying. The malware also attempts to terminate security processes during encryption. Known aliases and related naming include payoutsking, payouts_king, payoutsking_group, and payouts_king_ransomware. The actor has at times presented itself as not operating as a ransomware-as-a-service platform, but available reporting consistently characterizes it as a ransomware and extortion threat actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
49 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Initial access broker supporting ransomware-style intrusions through Microsoft Teams impersonation, credential harvesting, and deployment of browser backdoor malware.
Threat group using hidden Alpine Linux virtual machines via QEMU on compromised hosts to evade detection and maintain backdoor access in ransomware operations.
Referenced as a ransomware group for which UNC6692 is known to broker initial access.
A Payouts King-associated initial access broker is conducting social-engineering-led intrusions, using Microsoft Teams phishing and a malicious Microsoft Edge extension to gain host access and then sell that access for follow-on ransomware attacks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.