Payouts King is a financially motivated ransomware and data-extortion operation first observed in April 2025. It is also referred to as PayoutsKing, Payouts Kings, and PayoutsKing Group. Activity observed from early 2026 has been attributed with high confidence to Payouts King and shows substantial tradecraft overlap with former BlackBasta affiliates. The operation has also been associated with GOLD ENCOUNTER and has described itself as not operating as ransomware-as-a-service. Payouts King uses social-engineering-led initial access, including email bombing, impersonation of internal IT personnel through Microsoft Teams, phishing, vishing, and abuse of Quick Assist to obtain remote control of victim endpoints. An initial-access broker associated with the operation has deployed Edgecution, a malicious Microsoft Edge extension and native Python backdoor framework. Edgecution abuses browser native messaging to escape browser sandbox constraints, execute commands and PowerShell or Python code, write files, enumerate processes, fingerprint hosts, and maintain a persistent host-level foothold. Credential-phishing pages and remote-access lures support credential theft and follow-on ransomware access. The group has also used QEMU to operate concealed Alpine Linux virtual machines on compromised hosts. This virtualization-based tradecraft supports covert execution, credential collection, reverse SSH tunneling, command-and-control, Active Directory reconnaissance, data staging, and exfiltration while reducing endpoint-security visibility. Observed access vectors associated with this activity include exposed VPN infrastructure, exploitation of public-facing vulnerabilities, and Teams-based social engineering. Payouts King ransomware employs extensive anti-analysis and defense-evasion mechanisms, including runtime string decryption, hashed API resolution, direct system calls to evade endpoint hooks, security-process termination, scheduled-task persistence and elevation, deletion of shadow copies, event-log clearing, and recycle-bin cleanup. It encrypts data using AES-256-CTR with RSA-4096-protected per-file material and uses partial encryption for larger files to accelerate impact. The operation steals data before encryption and applies double extortion through a Tor-based leak site, threatening public disclosure of victim data. Publicly claimed victims include U.S. construction, manufacturing and defense-supply-chain organizations and a healthcare provider.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
46 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claimed responsibility for unauthorized access to Turner Construction systems and alleged theft of 27.2 TB of data, including employee personal and banking data as well as engineering, military-project, contractual, and ITAR-protected documents.
Claimed a ransomware attack against Turner Construction, alleging exfiltration of 27.2 TB of confidential data and publication of the victim's domain on its dark-web leak portal, consistent with data-extortion activity.
Initial access broker supporting ransomware-style intrusions through Microsoft Teams impersonation, credential harvesting, and deployment of browser backdoor malware.
Threat group using hidden Alpine Linux virtual machines via QEMU on compromised hosts to evade detection and maintain backdoor access in ransomware operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.