CARDS
CARDS
PayoutsKING is a profit-driven ransomware group that emerged in April 2025, linked to former affiliates of the BlackBasta operation which disbanded in February 2025. This group is known for its sophisticated evasion techniques, including obfuscation, the use of direct system calls to bypass endpoint detection and response (EDR) solutions, and a unique method of hiding malicious activity inside a QEMU virtual machine to avoid detection. PayoutsKING primarily employs double extortion tactics, involving data theft before encryption and subsequently posting victim data on dark web leak sites to pressure payments. While some reports indicate the group claims not to operate as a Ransomware-as-a-Service (RaaS) and performs attacks directly, evidence suggests a continuation of the BlackBasta affiliate playbook, with former BlackBasta affiliates aligning with PayoutsKING to carry out campaigns.
This profile is generated from the same canonical actor-card record used by the Threat Actor Cards directory, so aliases, targeting fields, activity notes, and source links stay aligned as the database is enriched.
Actor Card Detail
Identity
Aliases1
Source Boundary
SOCRadar is the retained baseline for this profile. IntelliOS preserves source labels as discovery and comparison signals until a cited source explicitly supports a merge, split, or actor-boundary change.
Targeting
Associated Activity1
ATT&CK IDs1
Campaign Context
No source-backed campaign or named operation association is currently retained for this actor card. Related campaign rows will appear here when SOCRadar, MITRE ATT&CK Campaigns, Microsoft, Google/Mandiant, CrowdStrike, CISA, or another retained public source ties the actor to a named campaign or operation.
Indicators
SOCRadar reports 840 IOCs for this profile. IntelliOS currently retains 93 cited public observable/context rows; this is not the full possible public-source IOC corpus.
Source coverage: 7 source groups tracked; 7 currently contribute retained observable or context rows.
Retained Observables
Showing 60 of 93
| Type | Value | Source |
|---|---|---|
| SHA-256 Hash | 335ad12a950f885073acdfebb250c93fb28ca3f374bbba5189986d9234dcbff43 | Payouts King Takes Aim at the Ransomware Throne |
| SHA-256 Hash | 3d1158884fb339b3328bd330fcc27598e1f1c94bcac39e75d1a272afa4deee1a4 | Payouts King IAB deploys Edgecution malware |
| SHA-256 Hash | a08d8e63b0cd3638fb40b8e6da546e26da69439597565827f9cec87915f785684 | Payouts King IAB deploys Edgecution malware |
| SHA-256 Hash | d68ce82e82801cd487f9cd2d24f7b30e353cafd0704dcdf0bb8f12822d4227c23 | Payouts King Takes Aim at the Ransomware Throne |
| Filename | readme_locker.txt3 | Payouts King Takes Aim at the Ransomware Throne |
| Command Line | Mozilla\ElevateTask scheduled-task namespace5 | Payouts King ransomware linked to BlackBasta |
| Command Line | Mozilla\UpdateTask scheduled-task namespace5 | Payouts King ransomware linked to BlackBasta |
| Command Line | Payouts King command-line parameter: -backup3 | Payouts King Takes Aim at the Ransomware Throne |
| Command Line | Payouts King command-line parameter: -i [identity string]3 | Payouts King Takes Aim at the Ransomware Throne |
| Command Line | Payouts King command-line parameter: -log [filename]3 | Payouts King Takes Aim at the Ransomware Throne |
| Command Line | Payouts King command-line parameter: -mode [all, local, share]3 | Payouts King Takes Aim at the Ransomware Throne |
| Command Line | Payouts King command-line parameter: -noelevate3 | Payouts King Takes Aim at the Ransomware Throne |
| Command Line | Payouts King command-line parameter: -nohide3 | Payouts King Takes Aim at the Ransomware Throne |
| Command Line | Payouts King command-line parameter: -nopersist3 | Payouts King Takes Aim at the Ransomware Throne |
| Command Line | Payouts King command-line parameter: -note3 | Payouts King Takes Aim at the Ransomware Throne |
| Command Line | Payouts King command-line parameter: -path [path]3 | Payouts King Takes Aim at the Ransomware Throne |
| Command Line | Payouts King command-line parameter: -percent [integer]3 | Payouts King Takes Aim at the Ransomware Throne |
| Command Line | Payouts King command-line parameter: -time [seconds]3 | Payouts King Takes Aim at the Ransomware Throne |
| Command Line | vssadmin.exe delete shadows /all /quiet3 | Payouts King Takes Aim at the Ransomware Throne |
| Tool / Process | Azorult credential-theft context2 | SOCRadar |
| Tool / Process | Chrome native messaging protocol abuse4 | Payouts King IAB deploys Edgecution malware |
| Tool / Process | Cracked panel kits3 | Payouts King Takes Aim at the Ransomware Throne |
| Tool / Process | Custom CRC checksum obfuscation3 | Payouts King Takes Aim at the Ransomware Throne |
| Tool / Process | Data theft before selective encryption3 | Payouts King Takes Aim at the Ransomware Throne |
| Tool / Process | Direct extortion and double-extortion pressure3 | Payouts King Takes Aim at the Ransomware Throne |
| Tool / Process | Direct system calls for process termination3 | Payouts King Takes Aim at the Ransomware Throne |
| Tool / Process | Edgecution browser-extension backdoor4 | Payouts King IAB deploys Edgecution malware |
| Tool / Process | FNV1 API/string hashing3 | Payouts King Takes Aim at the Ransomware Throne |
| Tool / Process | Headless Microsoft Edge execution3 | Payouts King Takes Aim at the Ransomware Throne |
| Tool / Process | Microsoft Teams impersonation lure3 | Payouts King Takes Aim at the Ransomware Throne |
| Tool / Process | OpenSSL-linked ransomware encryption3 | Payouts King Takes Aim at the Ransomware Throne |
| Tool / Process | Phishing templates3 | Payouts King Takes Aim at the Ransomware Throne |
| Tool / Process | Python-based native host backdoor4 | Payouts King IAB deploys Edgecution malware |
| Tool / Process | Quick Assist remote-support abuse3 | Payouts King Takes Aim at the Ransomware Throne |
| Tool / Process | RedLine credential-theft context2 | SOCRadar |
| Tool / Process | Remote Desktop Protocol access3 | Payouts King Takes Aim at the Ransomware Throne |
| Tool / Process | RSA-4096 and AES-256-CTR encryption3 | Payouts King Takes Aim at the Ransomware Throne |
| Tool / Process | Spam bombing and vishing social engineering3 | Payouts King Takes Aim at the Ransomware Throne |
| Tool / Process | Windows event-log clearing3 | Payouts King Takes Aim at the Ransomware Throne |
| Tool / Process | Windows shadow copy deletion3 | Payouts King Takes Aim at the Ransomware Throne |
| ATT&CK ID | T1005 - Data from Local System5 | Payouts King ransomware linked to BlackBasta |
| ATT&CK ID | T1027 - Obfuscated Files or Information5 | Payouts King ransomware linked to BlackBasta |
| ATT&CK ID | T1027.007 - Dynamic API Resolution5 | Payouts King ransomware linked to BlackBasta |
| ATT&CK ID | T1039 - Data from Network Shared Drive5 | Payouts King ransomware linked to BlackBasta |
| ATT&CK ID | T1041 - Exfiltration Over C2 Channel5 | Payouts King ransomware linked to BlackBasta |
| ATT&CK ID | T1053.005 - Scheduled Task5 | Payouts King ransomware linked to BlackBasta |
| ATT&CK ID | T1059.003 - Windows Command Shell5 | Payouts King ransomware linked to BlackBasta |
| ATT&CK ID | T1070.001 - Clear Windows Event Logs5 | Payouts King ransomware linked to BlackBasta |
| ATT&CK ID | T1204.002 - User Execution: Malicious File5 | Payouts King ransomware linked to BlackBasta |
| ATT&CK ID | T1219 - Remote Access Software5 | Payouts King ransomware linked to BlackBasta |
| ATT&CK ID | T1486 - Data Encrypted for Impact5 | Payouts King ransomware linked to BlackBasta |
| ATT&CK ID | T1489 - Service Stop5 | Payouts King ransomware linked to BlackBasta |
| ATT&CK ID | T1490 - Inhibit System Recovery5 | Payouts King ransomware linked to BlackBasta |
| ATT&CK ID | T1546 - Event Triggered Execution5 | Payouts King ransomware linked to BlackBasta |
| ATT&CK ID | T1562.001 - Impair Defenses5 | Payouts King ransomware linked to BlackBasta |
| ATT&CK ID | T1566 - Phishing5 | Payouts King ransomware linked to BlackBasta |
| ATT&CK ID | T1566.004 - Spearphishing Voice / vishing context5 | Payouts King ransomware linked to BlackBasta |
| ATT&CK ID | T1567 - Exfiltration Over Web Service5 | Payouts King ransomware linked to BlackBasta |
| Alias / Related Name | Payout$King2 | SOCRadar |
| Alias / Related Name | Payouts King2 | SOCRadar |
| Alias / Related Name | Payouts_KING2 | SOCRadar |
| Alias / Related Name | PayoutsKING2 | SOCRadar |
| Alias / Related Name | PayoutsMafia2 | SOCRadar |
| Alias / Related Name | PK Crew2 | SOCRadar |
| Network Indicator | wss://d1jp293q9tvi92.cloudfront[.]net/ws4 | Payouts King IAB deploys Edgecution malware |
| Network Indicator | wss://d23l50n6ubud7p.cloudfront[.]net/ws4 | Payouts King IAB deploys Edgecution malware |
| Network Indicator | wss://d2g6dl71gua1qa.cloudfront[.]net/ws4 | Payouts King IAB deploys Edgecution malware |
| Network Indicator | wss://d3nh8sl98s2554.cloudfront[.]net/ws4 | Payouts King IAB deploys Edgecution malware |
| Campaign Context | April 16, 2026: Zscaler published technical Payouts King analysis with sample hashes, command-line parameters, persistence artifacts, and encryption/evasion behavior.3 | Payouts King Takes Aim at the Ransomware Throne |
| Campaign Context | April 17, 2026: SOC Prime published detection and response context derived from Zscaler's Payouts King report.5 | Payouts King ransomware linked to BlackBasta |
| Campaign Context | IntelliOS excludes raw leak-site URLs, Tox/contact identifiers, victim lists, and scraped extortion material from the retained public observables table.6 | WatchGuard ransomware tracker |
| Campaign Context | June 23, 2026: Zscaler reported Edgecution, a browser-extension/Python backdoor delivery mechanism tied to a Payouts King-associated initial access broker.4 | Payouts King IAB deploys Edgecution malware |
| Campaign Context | SOCRadar and WatchGuard are retained for baseline actor-card and ransomware-tracker context; Zscaler remains the controlling public technical source for retained hashes and Edgecution infrastructure. | Retained source |
| COUNTRY | Canada6 | WatchGuard ransomware tracker |
| COUNTRY | France6 | WatchGuard ransomware tracker |
| COUNTRY | Germany6 | WatchGuard ransomware tracker |
| COUNTRY | United States6 | WatchGuard ransomware tracker |
| OBSERVABLE | SOC Prime retains detection-hunting context for scheduled-task persistence, suspicious VSSADMIN activity, Payouts King sample hashes, and process-creation telemetry.5 | Payouts King ransomware linked to BlackBasta |
| OBSERVABLE | SOCRadar describes PayoutsKING as a newly identified ransomware group with healthcare, manufacturing, and education targeting and RaaS-style extortion behavior.2 | SOCRadar |
| OBSERVABLE | SOCRadar retains PayoutsKING as a ransomware group with PK Crew, Payout$King, Payouts_KING, payoutsking, and PayoutsMafia aliases.2 | SOCRadar |
| OBSERVABLE | WatchGuard tracks Payouts King as active and classifies the public extortion model as direct and double extortion with free-data-leak pressure; IntelliOS does not republish raw contact, onion, or victim-list material.6 | WatchGuard ransomware tracker |
| OBSERVABLE | Zscaler assesses some activity consistent with former BlackBasta initial access broker tradecraft as Payouts King with high confidence; IntelliOS treats that as source-backed ecosystem context, not a blanket BlackBasta merge.3 | Payouts King Takes Aim at the Ransomware Throne |
| OBSERVABLE | Zscaler describes spam bombing, Microsoft Teams impersonation, and Quick Assist as recurring intrusion setup for Payouts King-aligned activity.3 | Payouts King Takes Aim at the Ransomware Throne |
| OBSERVABLE | Zscaler's Edgecution report ties an initial-access broker associated with Payouts King to a headless Microsoft Edge extension plus Python native-host backdoor.4 | Payouts King IAB deploys Edgecution malware |
| RANSOM_NOTE | readme_locker.txt ransom-note filename; do not republish contact IDs, onion URLs, or victim lists from extortion trackers.6 | WatchGuard ransomware tracker |
| REGION | Europe2 | SOCRadar |
| REGION | North America2 | SOCRadar |
| SECTOR | Education6 | WatchGuard ransomware tracker |
| SECTOR | Healthcare6 | WatchGuard ransomware tracker |
| SECTOR | Hospitals6 | WatchGuard ransomware tracker |
| SECTOR | Manufacturing6 | WatchGuard ransomware tracker |
| SECTOR | North America and Europe exposed organizations2 | SOCRadar |
| SECTOR | Professional services6 | WatchGuard ransomware tracker |
| Source | Reported | Retained | Coverage Status |
|---|---|---|---|
| SOCRadar2 | 840 | 13 | Reported IOC count and SOCRadar-backed observable rows retained in IntelliOS. |
| SOCRadar1 | N/A | 1 | Public observables or source-context rows retained and displayed. |
| SOCRadar2 | N/A | 13 | Public observables or source-context rows retained and displayed. |
| Zscaler ThreatLabz3 | N/A | 34 | Public observables or source-context rows retained and displayed. |
| Zscaler ThreatLabz4 | N/A | 11 | Public observables or source-context rows retained and displayed. |
| SOC Prime5 | N/A | 22 | Public observables or source-context rows retained and displayed. |
| WatchGuard6 | N/A | 12 | Public observables or source-context rows retained and displayed. |
IntelliOS Intel Products
None Found
Source Reconciliation
| Source | Primary Name | Treatment | Boundary |
|---|---|---|---|
| SOCRadar | PayoutsKING | Baseline actor-card record retained for the current profile view. | Fields reflect the retained database record. Additional source consensus, collisions, and canonical identity mappings can be layered into this profile without automatically merging actors. |
| IntelliOS | PayoutsKING | Normalizes this record for directory search, card display, profile lookup, and future product linking. | Normalization is a presentation and workflow aid; it is not an independent attribution claim. |
Citations
| # | Source | Use In Card |
|---|---|---|
| 1 | SOCRadar Threat Actor Database https://socradar.io/free-tools/threat-actor/ransomware | Baseline actor-card corpus source for retained profile fields. |
| 2 | SOCRadar Actor Profile https://socradar.io/free-tools/ransomware-intelligence/groups/payoutsking | Per-actor SOCRadar profile source for ransomware profile metadata and IOC count when available. |
| 3 | Payouts King Takes Aim at the Ransomware Throne https://www.zscaler.com/blogs/security-research/payouts-king-takes-aim-ransomware-throne | Threat Research |
| 4 | Payouts King IAB deploys Edgecution malware https://www.zscaler.com/blogs/security-research/payouts-king-ransomware-initial-access-broker-deploys-new-edgecution | Threat Research |
| 5 | Payouts King ransomware linked to BlackBasta https://socprime.com/active-threats/payouts-king-takes-aim-at-the-ransomware-throne/ | Detection Engineering |
| 6 | WatchGuard ransomware tracker: Payouts King https://www.watchguard.com/wgrd-security-hub/ransomware-tracker/payouts-king | Ransomware Tracker |
Source Collision Notes
IntelliOS starts this detail page from the retained source record for PayoutsKING.
No possible same-actor, alias reuse, sub-cluster, duplicate-boundary, or external-source collision is currently retained for this actor.
| Collision Source | Candidate Records | Shared Evidence | Treatment |
|---|---|---|---|
| None retained | No candidate records | No shared evidence recorded | No collision action needed. |
| External sources | Mandiant, CrowdStrike, other non-SOCRadar sources | None retained | External collisions are shown separately when retained. |