PayloadBIN is a Windows ransomware family associated with the Evil Corp cybercrime cluster and widely assessed as part of the same lineage as WastedLocker, Hades, and Phoenix Locker. It emerged as a continuation or rebranding of Phoenix Locker during Evil Corp’s broader pattern of renaming ransomware operations after U.S. sanctions complicated ransom payment facilitation and increased attribution pressure. Some reporting has also noted that attacks involving PayloadBIN may have been misattributed to other actors because of this deliberate rebranding strategy.
PayloadBIN encrypts victim files and is reported to append a distinctive new extension to encrypted data while dropping a ransom note identifying the PayloadBIN brand. Code-analysis reporting has linked it closely to Phoenix Locker and, by extension, to Hades and WastedLocker, citing substantial overlap in core functionality such as file enumeration and other implementation details. It has also been tied to the same broader tooling ecosystem used by Evil Corp, including packed samples associated with CryptOne in the relevant period.
Operationally, PayloadBIN fits the Evil Corp model of targeted enterprise ransomware intrusions rather than indiscriminate commodity deployment. Across this lineage, intrusions have involved initial access through phishing-delivered Dridex in earlier periods and later shifts toward SocGholish and Cobalt Strike to obscure attribution, with post-compromise activity including credential theft, reconnaissance, lateral movement, data exfiltration, and defense evasion before encryption. PayloadBIN has also been referenced in connection with Yanluowang-linked activity, indicating either shared use, code access, or attribution confusion around some incidents. The malware is primarily associated with financially motivated attacks against corporate environments across multiple sectors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Beyond targets, the chat logs also highlighted Yanluowang’s use of the ransomware, PayloadBIN but also that attacks that involved it may potentially have been misattributed to another ransomware actor, Evil Corp.
"...shifted to using ransomware variants such as ... Payload.bin."
11 distinct techniques documented for this family, organized by ATT&CK tactic.
calls STS GetCallerIdentity / AssumeRole, and enumerates Secrets Manager (ListSecrets / GetSecretValue) across 16+ regions | npm: validates tokens through /-/whoami and enumerates publish access through /-/npm/v1/tokens... Stolen npm publish tokens enable downstream supply-chain pivoting
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as ransomware used by Yanluowang, with some attacks involving it potentially misattributed to Evil Corp.
Ransomware payload/variant referenced as used by GOLD DRAKE/Evil Corp after sanctions.
Ransomware payload/variant referenced as used by GOLD DRAKE/Evil Corp after sanctions.
Ransomware continuation of Phoenix Locker with substantial function overlap, including nearly identical file enumeration logic, and part of the same Evil Corp-linked code lineage.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.