Activity timeline
Payouts King appears in 4 tracked threats between and ; the busiest month was 2026-04 with 2 reports.
ATT&CK techniques observed
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 4 of 4 tracked threats
- T1486 Data Encrypted for Impact — Impactobserved in 4 of 4 tracked threats
- T1685 Disable or Modify Tools — Defense Impairmentobserved in 4 of 4 tracked threats
- T1036.005 Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion)observed in 3 of 4 tracked threats
- T1059.001 PowerShell — Executionobserved in 3 of 4 tracked threats
- T1070.004 File Deletion — Stealth (formerly Defense Evasion)observed in 3 of 4 tracked threats
- T1071.001 Web Protocols — Command and Controlobserved in 3 of 4 tracked threats
- T1082 System Information Discovery — Discoveryobserved in 3 of 4 tracked threats
- T1083 File and Directory Discovery — Discoveryobserved in 3 of 4 tracked threats
- T1105 Ingress Tool Transfer — Command and Controlobserved in 3 of 4 tracked threats
- T1204.002 User Execution: Malicious File — Executionobserved in 3 of 4 tracked threats
- T1219 Remote Access Tools — Command and Controlobserved in 3 of 4 tracked threats
- T1489 Service Stop — Impactobserved in 3 of 4 tracked threats
- T1490 Inhibit System Recovery — Impactobserved in 3 of 4 tracked threats
- T1003.001 LSASS Memory — Credential Accessobserved in 2 of 4 tracked threats
Tracked threats
- Edgecution: Payouts King Initial Access Broker Deploys Malicious Microsoft Edge Extension with Embedded Python BackdoorHIGH
- Payouts King Ransomware — BlackBasta-Affiliate RaaS Evades EDR via Direct System Calls, ntdll Export-Table Walking, and SetFileInformationByHandle Rename Evasion (Zscaler ThreatLabz)HIGH
- Payouts King Ransomware Uses QEMU Virtual Machines to Bypass EDR and Endpoint Security ControlsHIGH
- Payouts King Ransomware — BlackBasta Successor Operation Targeting US Manufacturing, Healthcare, and Construction SectorsHIGH