Skip to main content
Mallory
2 malware families

STAC4713

Also known asSTAC4713

STAC4713 is a financially motivated intrusion cluster first observed by Sophos in November 2025 and linked with high confidence to data theft and deployment of PayoutsKing ransomware. Sophos associates STAC4713 with the GOLD ENCOUNTER threat group. The campaign abuses QEMU to run hidden Alpine Linux 3.22.0 virtual machines on compromised hosts as a core defense-evasion and covert-access mechanism, making activity inside the guest largely invisible to host-based endpoint security tools. In STAC4713 intrusions, attackers create a scheduled task named TPMProfiler to launch qemu-system-x86_64.exe as SYSTEM, booting a virtual disk image disguised as files such as vault.db and later bisrv.dll. The VM establishes covert access via port forwarding from ports 32567 and 22022 to SSH port 22 and uses AdaptixC2 or OpenSSH to create a reverse SSH tunnel. Tools observed in the VM include AdaptixC2, Chisel, BusyBox, Rclone, wg-obfuscator, and Linker2/tinker2. Post-compromise activity included credential theft and Active Directory data collection, including use of vssuirun.exe to create shadow copies and the print command over SMB to copy NTDS.dit and the SAM and SYSTEM hives, as well as network share discovery and file access using legitimate tools such as Microsoft Paint, Notepad, Microsoft Edge, and WizTree. Reported initial access vectors for STAC4713 included exposed SonicWall VPNs without MFA and exploitation of SolarWinds Web Help Desk vulnerability CVE-2025-26399; later reporting also noted exposed Cisco SSL VPNs and social engineering via phishing, fake Microsoft Teams IT support, and Quick Assist. Sophos reported that from early 2026, GOLD ENCOUNTER shifted in some PayoutsKing-linked incidents away from QEMU-based covert access toward sideloading Havoc C2 via ADNotificationManager.exe and exfiltration with Rclone. PayoutsKing is described as a direct-operations ransomware actor rather than a ransomware-as-a-service model and is focused on hypervisor environments, with encryptors targeting VMware and ESXi. Known alias/sub-group relationship directly mentioned in the content: GOLD ENCOUNTER is the threat group associated with STAC4713; STAC4713 is linked to the PayoutsKing ransomware operation.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

10 of 15 tactics24 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
3 techniques
T1078
Valid Accounts
T1133
External Remote Services
T1190×2
Exploit Public-Facing Application
TA0002
Execution
1 technique
T1053
Scheduled Task/Job
T1053.005×2
Scheduled Task
TA0003
Persistence
3 techniques
T1053
Scheduled Task/Job
T1053.005×2
Scheduled Task
T1078
Valid Accounts
T1133
External Remote Services
TA0004
Privilege Escalation
2 techniques
T1053
Scheduled Task/Job
T1053.005×2
Scheduled Task
T1078
Valid Accounts
TA0005
Stealth
3 techniques
T1036
Masquerading
T1078
Valid Accounts
T1497×2
Virtualization/Sandbox Evasion
TA0006
Credential Access
1 technique
T1003
OS Credential Dumping
TA0007
Discovery
2 techniques
T1046
Network Service Discovery
T1497×2
Virtualization/Sandbox Evasion
TA0008
Lateral Movement
1 technique
T1021
Remote Services
T1021.004
SSH
TA0011
Command and Control
2 techniques
T1090
Proxy
T1090.002×2
External Proxy
T1105
Ingress Tool Transfer
TA0040
Impact
1 technique
T1486
Data Encrypted for Impact
ACTIVITY FEED

Recent activity

5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping12

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal2

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.