Payouts King is an emerging ransomware and extortion group first observed in 2025 and widely assessed as linked to former BlackBasta affiliates. Reporting has associated the operation with the GOLD ENCOUNTER cluster and noted strong tradecraft overlap with BlackBasta-era intrusion patterns, particularly social-engineering-led initial access, rapid privilege escalation, data theft, and double extortion through a leak site. The group has targeted organizations across multiple sectors, including manufacturing, healthcare, technology, government, and other enterprises, with a notable concentration of victims in North America and Europe. Payouts King commonly relies on human-operated intrusion techniques rather than purely exploit-driven deployment. Observed access methods include spam bombing, phishing and vishing, impersonation of internal IT staff over Microsoft Teams, and abuse of Quick Assist or similar remote-access workflows to obtain hands-on keyboard access. Activity tied to an initial access broker associated with the group has also used a malicious Microsoft Edge extension campaign known as Edgecution, which abused Chrome Native Messaging to bridge browser execution to a host-level Python backdoor. Separate reporting has linked Payouts King intrusions to exposed VPN appliances and exploitation of enterprise software vulnerabilities. Once inside a victim environment, the group has been observed establishing persistence through scheduled tasks, escalating privileges to SYSTEM, conducting reconnaissance, harvesting credentials, and exfiltrating sensitive data prior to encryption. Payouts King has also been associated with the use of QEMU-based hidden virtual machines to evade host-based security monitoring and maintain covert access, including reverse-SSH-style tunneling and staging of post-exploitation tooling inside guest environments. This virtualization-backed tradecraft distinguishes the group from many commodity ransomware operators and reflects a focus on stealth and defense evasion. The ransomware itself uses strong hybrid cryptography, including RSA-4096 and AES-256 in CTR mode, and supports intermittent or partial encryption of larger files to accelerate impact. Public reverse-engineering has highlighted extensive anti-analysis and anti-detection measures, including runtime string decryption, hashed API resolution, custom checksum-based obfuscation, direct system calls to bypass user-mode security hooks, and logic intended to frustrate sandbox execution. The malware has also been observed terminating security-related processes, deleting shadow copies, clearing event logs, and otherwise impairing recovery and forensic visibility. Associated ransom notes direct victims to contact the operators through anonymized channels and reference the group’s leak infrastructure. Known aliases include payoutsking, payouts_king, payoutsking_group, and payouts_king_ransomware. Payouts King is best understood as a financially motivated ransomware actor rather than a state-sponsored threat actor, although some victim claims have involved sensitive industrial and defense-adjacent data. The group’s operational profile indicates a mature, hands-on intrusion capability shaped by the post-BlackBasta ransomware ecosystem and supported, at least in some cases, by specialized initial access brokers.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
48 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Payouts King-associated initial access broker is conducting social-engineering-led intrusions, using Microsoft Teams phishing and a malicious Microsoft Edge extension to gain host access and then sell that access for follow-on ransomware attacks.
Associated with ransomware-linked initial access activity using the Edgecution malicious Microsoft Edge extension to bridge from a hidden browser instance to a host-level Python backdoor on Windows.
Referenced as the ransomware group tied to the initial access broker linked to the Edgecution malware campaign.
Ransomware group active since April 2025, with increased activity in early 2026 linked to former BlackBasta affiliates. It conducts double-extortion style attacks by stealing sensitive data and selectively encrypting files, while operating a dark web leak site to pressure victims.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.