STAC4713 is a financially motivated intrusion cluster first observed in November 2025 and linked to the PayoutsKing ransomware operation. The activity has been attributed to GOLD ENCOUNTER, a threat group associated with hypervisor-focused ransomware operations, including encryptors for VMware and ESXi environments. PayoutsKing is assessed to be a directly operated ransomware and extortion operation rather than a ransomware-as-a-service model. A defining characteristic of STAC4713 is the abuse of QEMU to run a hidden Alpine Linux virtual machine on compromised hosts as a defense-evasion and covert-access mechanism. Operators created a SYSTEM-level scheduled task to launch the virtual machine, disguised the virtual disk image as benign-looking files, and used port forwarding plus reverse SSH tunneling for concealed remote access. Tooling observed inside the virtualized environment included AdaptixC2, OpenSSH, Chisel, BusyBox, wg-obfuscator, and Rclone, enabling tunneling, obfuscation, remote control, and data transfer while reducing visibility to host-based security products. Observed tradecraft includes initial access through exposed VPN infrastructure lacking multi-factor authentication, exploitation of CVE-2025-26399 in SolarWinds Web Help Desk, and later social-engineering operations involving phishing and fake IT support over Microsoft Teams to induce installation of remote access tools. Post-compromise activity included credential theft and collection of Active Directory data, use of shadow copies to access protected files, reconnaissance of network shares and domain environments, exfiltration with Rclone, and deployment of PayoutsKing ransomware. In some 2026 intrusions, operators also used DLL sideloading to deploy Havoc C2 payloads, indicating tactical adaptation away from QEMU in certain cases while retaining the same broader operational objective of data theft and extortion. STAC4713 overlaps with the broader GOLD ENCOUNTER / PayoutsKing ecosystem and has been associated with extortion activity alongside ransomware deployment. The cluster is notable for combining virtualization-based defense evasion, covert persistence, credential access, data theft, and ransomware execution in enterprise environments, especially those with virtualization infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat activity cluster involved in ransomware attacks using AdaptixC2 and associated with PayoutsKing ransomware.
Attack campaign using hidden QEMU virtual machines as a core evasion method to conceal operations, harvest credentials, and stage ransomware deployments. The infection chain includes a scheduled task named “TPMProfiler,” QEMU execution under SYSTEM, disguised virtual disk images, port forwarding, reverse SSH tunnels, and an Alpine Linux VM loaded with attacker tooling.
Financially motivated campaign using QEMU virtual machines to conceal activity, maintain hidden access, steal credentials and data, and support deployment of PayoutsKing ransomware.
An activity cluster linked to the Payouts King operation that deploys hidden QEMU virtual machines, steals credentials, and uses multiple initial access vectors including exposed VPNs and social engineering.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.