Payload is an emerging ransomware threat actor and malware family first identified in February 2026. It operates a cross-platform ransomware capability with Windows and Linux variants, including a Linux ELF encryptor tailored for VMware ESXi environments and a Windows variant designed for broad enterprise impact. Reported victimology indicates a focus on mid-to-large organizations across multiple sectors, especially healthcare, telecommunications, finance, logistics, manufacturing, technology, hospitality, energy, and public-sector entities. Known aliases include payload_ransomware. Payload’s Linux variant targets virtualized infrastructure by enumerating ESXi virtual machine inventory, shutting down running virtual machines, and encrypting large virtual disk-related files. The malware parses VMware inventory data to identify relevant paths, uses multithreaded processing, and applies partial encryption optimized for large files. The Windows variant supports extensive operator-controlled execution options, can enumerate local and network-accessible storage, and uses a hybrid cryptographic design based on Curve25519 key exchange and ChaCha20 encryption. Payload has been described as offline ransomware because encryption and key generation occur locally without requiring command-and-control infrastructure for key exchange. The group demonstrates mature defense-evasion and anti-forensics tradecraft. Reported behaviors include runtime string obfuscation, anti-debugging checks, self-deletion, disabling Event Tracing for Windows, clearing event logs, deleting shadow copies, and terminating backup, database, security, and productivity-related processes and services prior to encryption. Payload also uses multithreaded encryption pipelines sized to available CPU resources and selects optimized cryptographic implementations based on processor capabilities. Observed operations indicate conventional ransomware deployment with file encryption and ransom-note delivery, and multiple incidents are described as involving data breaches, supporting the assessment that Payload also engages in data-theft extortion. Reported victims span North America, Europe, Asia, Africa, and Latin America, with repeated activity against organizations in the United States and additional victims in countries including Germany, Switzerland, Malaysia, Colombia, Brazil, and the United Kingdom.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack resulting in a data breach against Zara Investment Holding.
Named as the ransomware group responsible for the attack against B&B Hydraulik, a German manufacturing company.
Ransomware group attributed with conducting an attack against Stücheli Architekten, a Swiss architectural firm in the professional services sector.
Conducting a ransomware attack against Baya Technologies.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.