Payload, also tracked as PAYLOAD and payload_ransomware, is a financially motivated ransomware and extortion operation first identified in February 2026. It targets mid-to-large-sized organizations across manufacturing, technology, healthcare, telecommunications, financial services, logistics, and retail. Its operations span multiple regions, including the Middle East, Asia, Europe, and North America. Payload affiliates obtain initial access using compromised VPN credentials, including access supplied by initial access brokers through the FortiBleed credential-compromise campaign. These downstream relationships do not establish that Payload itself operates FortiBleed or is part of INC or Lynx. Payload has conducted encryption-less extortion as well as conventional ransomware attacks. In an attack against a Middle Eastern manufacturer, operators entered through a compromised VPN account, obtained domain administrator privileges, and abused Active Directory Group Policy Objects linked at the domain root. These policies distributed ransom demands, changed workstation wallpapers and login messaging, restricted workstation access, disabled local administrator accounts, and disabled Windows Firewall. The attackers exfiltrated organizational data and published it on the dark web without deploying conventional ransomware executables or encrypting files. Payload ransomware includes Windows and Linux variants, with the Linux variant targeting VMware ESXi environments. Both use Curve25519 key exchange and ChaCha20 encryption, multithreaded processing, and partial encryption of large files. The ESXi variant enumerates virtual machines, powers them off, and targets large virtual disk files. The Windows variant can encrypt local storage and network shares, delete Volume Shadow Copies, terminate backup, database, and security services, disable Event Tracing for Windows, clear event logs, and delete itself. String obfuscation and anti-debugging checks further hinder analysis. Encryption and key generation occur locally without requiring a command-and-control connection for key exchange.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
32 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named extortion campaign whose operators controlled the victim’s Active Directory environment and used malicious group policy to demonstrate compromise and demand payment without encrypting data.
Identified in the FBI and US Secret Service advisory as a ransomware group connected to access obtained through FortiBleed. The article provides no group-specific operational details beyond this connection.
The report attributes a ransomware attack against musical-instrument and audio-equipment retailer Boullard Musique to payload. The breach was reportedly discovered on October 8, 2026, at 19:33 UTC. Victim-location information is inconsistent: the report lists France (FR), while its company description identifies Switzerland. It provides no technical evidence supporting the attribution or details about the ransomware family.
Payload lists Boullard Musique, a Swiss musical-instrument and audio-equipment retailer, as a victim, with a discovery date of October 8, 2026. The post provides no stolen-data details, compromise evidence, ransom amount, or deadline.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.