PAYLOAD is an emerging, financially motivated ransomware and cyber-extortion group first observed in February 2026. It has claimed and been linked to attacks against mid-sized and large organizations across multiple sectors, including manufacturing, technology, health care, telecommunications, financial services, logistics, energy, hospitality, real estate, food production, and public-sector entities. Reported victims span the United States, Switzerland, Germany, the Philippines, Mexico, the United Kingdom, Egypt, Jordan, South Africa, France, and Brazil. PAYLOAD operates Windows and Linux ransomware variants, including tooling designed to disrupt and encrypt VMware ESXi virtual-machine environments. Its ransomware uses hybrid Curve25519 and ChaCha20 cryptography, multithreaded and partial-encryption routines for large files, and locally generated per-file key material, enabling offline encryption without a key-exchange command-and-control requirement. The Windows variant can enumerate local and network-accessible storage, terminate backup, database, and security products, delete Volume Shadow Copies, clear Windows event logs, impair Event Tracing for Windows, and remove itself following execution. The ESXi-focused variant enumerates virtual-machine inventory, powers off virtual machines, and encrypts large virtual-disk data. In a documented intrusion against a Middle Eastern manufacturing organization, PAYLOAD gained access through a compromised VPN account and obtained domain-administrator privileges. Rather than relying on a conventional encryption payload, the operators abused Active Directory Group Policy Objects linked at the domain root to distribute ransom communications, modify desktop settings, disable local administrator accounts, and disable Windows Firewall across the domain after endpoint restart. The operation included data exfiltration and publication of stolen data, demonstrating that PAYLOAD can conduct encryption-less data-theft extortion as well as conventional ransomware operations. Its extensive use of native Active Directory administration and anti-forensic features can reduce visibility for defenses focused primarily on malicious binaries and processes.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
33 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Allegedly conducted a ransomware attack against Netech (Neeser Technik AG), a Swiss engineering and industrial-services company.
Conducted a ransomware-style extortion operation against a Middle Eastern manufacturing organization without deploying file-encrypting malware. The group used compromised VPN credentials, escalated to domain administrator, abused Active Directory Group Policy to distribute ransom notes, alter wallpapers and system configurations, deactivate local administrator accounts, disable Windows Firewall, exfiltrate data, and publish it on the dark web.
Ransomware/data theft activity targeting Qualiflex Datacenter and associated companies, with stolen data reported in the breach summary.
Conducting a ransomware attack resulting in a data breach against Zara Investment Holding.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.