Payouts King is a Windows ransomware family and associated double-extortion operation first observed in April 2025. Its operators steal sensitive organizational data, selectively deploy file encryption, and threaten publication through a Tor-hosted leak site. Victims include manufacturing, professional services, technology, and healthcare organizations, particularly in the United States and Germany. Sophos associates Payouts King intrusions with GOLD ENCOUNTER and tracks related activity as STAC4713. Some campaigns have also been linked to former BlackBasta affiliates, without establishing that these actors and GOLD ENCOUNTER are identical.
Observed intrusion methods include access through exposed SonicWall and Cisco SSL VPNs, SonicWall accounts lacking multifactor authentication, and exploitation of SolarWinds Web Help Desk vulnerability CVE-2025-26399. Social-engineering campaigns combine email bombing with Microsoft Teams calls impersonating internal IT support to persuade employees to grant remote access through Quick Assist. Post-compromise activity includes network-share discovery, theft of Active Directory and local account credential material, and data exfiltration using Rclone. Operators have concealed tools inside hidden QEMU virtual machines running Alpine Linux, using reverse SSH connectivity to reduce visibility to host-based endpoint security. Later observed intrusions used DLL sideloading to execute Havoc command-and-control payloads instead.
The ransomware encrypts files using per-file AES-256-CTR keys protected with RSA-4096. It supports encryption of local disks and network shares, configurable encryption scope, and intermittent encryption across 13 blocks for larger files. Scheduled tasks provide persistence and execution with SYSTEM privileges. Anti-analysis features include runtime string decryption, hashed API resolution, custom checksums, and an identity argument that must pass validation before encryption begins. When locked files impede encryption, the locker checks running processes against 131 checksummed names, largely associated with antivirus and endpoint detection products, and can terminate matching processes using direct system calls. It also deletes volume shadow copies, empties the recycle bin, and clears Windows event logs to inhibit recovery and investigation. Ransom-note creation is conditional on an operator-supplied option.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Sophos documented exploitation of SolarWinds Web Help Desk CVE-2025-26399 during a January 2026 Payouts King intrusion. | Payouts King steals large amounts of data, encrypts selectively, and posts victims to a Tor leak site.
The second campaign exploits the CitrixBleed 2 vulnerability to gain access, subsequently deploying a QEMU VM with manually installed tools for reconnaissance and data staging.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Payouts King steals large amounts of data, encrypts selectively, and posts victims to a Tor leak site.
A new ransomware group known as Payouts King has quietly been building a reputation since it first appeared in April 2025.
A relatively unknown ransomware group called Payouts King has emerged as a serious cybersecurity threat... Once a foothold is established on the victim’s network, Payouts King deploys its ransomware payload, steals large volumes of sensitive data, and then selectively encrypts files.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
The Payouts King ransomware... exhibits maturity through diverse initial access methods (including VPN exploitation, social engineering via Microsoft Teams, and vulnerability abuse)...
If the -nopersist parameter is not passed on the command-line, persistence is established using scheduled tasks... If the -noelevate parameter is not specified, Payouts King will schedule another task to elevate privileges and run as the SYSTEM user...
If the -nopersist parameter is not passed on the command-line, persistence is established using scheduled tasks... If the -noelevate parameter is not specified, Payouts King will schedule another task to elevate privileges and run as the SYSTEM user...
It builds and decrypts strings on the fly rather than storing them as readable text, making static analysis much harder.
It also resolves Windows functions using hash values instead of plain names, and applies a custom checksum algorithm with a unique seed per value, defeating tools that rely on pre-built hash tables to identify malware.
It attempts to gain full system-level privileges, deletes Windows shadow copies to block recovery, clears event logs to slow forensic investigations, and empties the recycle bin before starting encryption.
When a file cannot be opened for encryption since a security tool has locked it, the ransomware scans all running processes and checks them against a list of 131 known antivirus and endpoint detection software processes. | the ransom note named readme_locker.txt is only dropped when a specific command-line flag is provided at runtime, making automated sandbox analysis considerably harder.
...extensive post-compromise activity, such as credential extraction (e.g., NTDS.dit), Active Directory reconnaissance, and controlled data exfiltration.
If opening fails due to an error code 32 (ERROR_SHARING_VIOLATION), the ransomware will enumerate the running processes and compute a checksum value for each process name...
The following files are not encrypted... The following directories are also skipped... After the content of a file is encrypted, the file is renamed...
When a file cannot be opened for encryption since a security tool has locked it, the ransomware scans all running processes and checks them against a list of 131 known antivirus and endpoint detection software processes. | the ransom note named readme_locker.txt is only dropped when a specific command-line flag is provided at runtime, making automated sandbox analysis considerably harder.
They then impersonate an IT support employee, reaching out via Microsoft Teams and convincing the victim to initiate a Quick Assist session. Once access is granted, the attacker drops malware on the system, quietly establishing a foothold inside the organization’s network.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware that steals sensitive data before selectively encrypting files on compromised systems. It uses strong encryption (RSA-4096 and AES-256-CTR), deletes shadow copies, clears event logs, evades EDR through direct system calls and hashed API resolution, and pressures victims via a dark web leak site.
Ransomware selectively deployed in new attacks by former BlackBasta initial access brokers, alongside large-scale data theft.
Ransomware that conducts double-extortion operations by stealing sensitive data and selectively encrypting files. It uses RSA-4096 and AES-256-CTR encryption, partial encryption for large files, anti-analysis and anti-sandbox techniques, direct system calls to terminate security tools, and post-encryption cleanup such as deleting shadow copies and wiping event logs.
Ransomware linked to campaigns that abuse QEMU to run hidden Alpine Linux virtual machines for covert access, credential collection, persistence, evasion, and data exfiltration. The strain uses heavy obfuscation and anti-analysis mechanisms, establishes persistence via scheduled tasks, terminates security tools using low-level system calls, and encrypts files with AES-256 (CTR) and RSA-4096 using intermittent encryption for larger files.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.