Payload is a ransomware threat group active by 2026 and identified as an emerging or returning actor in the cyber extortion ecosystem. The group has been linked to multiple publicly reported ransomware intrusions and associated data breaches across a geographically diverse victim set. Observed victims span North America, Europe, Asia, and Latin America, indicating opportunistic international targeting rather than a narrowly regional focus. Payload has targeted organizations across a broad range of sectors, including manufacturing, technology, professional and business services, health care, hospitality, energy, real estate, consumer-facing businesses, and government or public-sector entities. Reported victims include industrial manufacturers, engineering consultancies, software and technology providers, medical institutions, hotels, property management firms, and public bodies. This breadth is consistent with financially motivated ransomware operations that prioritize victim availability and monetization potential over a single vertical specialization. The group is associated with ransomware attacks that were also characterized as data breaches, supporting assessment that Payload conducts extortion-oriented intrusions involving unauthorized access and data theft in addition to ransomware deployment. High-confidence reporting supports the use of initial compromise leading to post-compromise activity and exfiltration, but the available information does not reliably establish specific tradecraft such as privilege escalation, lateral movement, or particular malware deployment techniques for this actor. Known aliases include payload_ransomware. No high-confidence attribution to a specific state sponsor or country of origin is currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as the ransomware group responsible for the attack against B&B Hydraulik, a German manufacturing company.
Ransomware group attributed with conducting an attack against Stücheli Architekten, a Swiss architectural firm in the professional services sector.
Conducting a ransomware attack against Baya Technologies.
Conducting a ransomware attack against Hans & Jos. Kronenberg GmbH, a German manufacturing company.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.