Threadlinqs IntelligenceStart free

Threat actorRussiaTracked since 2026-04

Payouts King

Also known as:BlackBasta affiliateBlack Basta successorPayoutsKingPayouts-KingPK RansomwareRaaS-PKPayouts King Ransomware GangBlackBasta Successor

As of 2026-06-23, Payouts King is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 4 threats spanning malware, ransomware. Also known as BlackBasta affiliate, Black Basta successor, PayoutsKing, Payouts-King. ATT&CK coverage spans 68 techniques across 15 tactics in 4 of 4 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1486 (Data Encrypted for Impact), T1685 (Disable or Modify Tools).

Tracked threats
44 high
First seen
2026-04-16
Last seen
2026-06-23
ATT&CK techniques
68across 4 of 4 threats
Related CVEs
0None referenced
Attribution
RussiaNation or origin
Nation: Russia · 4 tracked threat(s) · Categories: MALWARE, RANSOMWARE

Activity timeline

Payouts King appears in 4 tracked threats between and ; the busiest month was 2026-04 with 2 reports.

ATT&CK techniques observed

68 techniques observed across 4 of 4 tracked threats · Initial Access (9), Execution (8), Stealth (formerly Defense Evasion) (8), Discovery (7), Collection (4), Command and Control (4)
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 4 of 4 tracked threats
  • T1486 Data Encrypted for Impact — Impactobserved in 4 of 4 tracked threats
  • T1685 Disable or Modify Tools — Defense Impairmentobserved in 4 of 4 tracked threats
  • T1036.005 Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion)observed in 3 of 4 tracked threats
  • T1059.001 PowerShell — Executionobserved in 3 of 4 tracked threats
  • T1070.004 File Deletion — Stealth (formerly Defense Evasion)observed in 3 of 4 tracked threats
  • T1071.001 Web Protocols — Command and Controlobserved in 3 of 4 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 3 of 4 tracked threats
  • T1083 File and Directory Discovery — Discoveryobserved in 3 of 4 tracked threats
  • T1105 Ingress Tool Transfer — Command and Controlobserved in 3 of 4 tracked threats
  • T1204.002 User Execution: Malicious File — Executionobserved in 3 of 4 tracked threats
  • T1219 Remote Access Tools — Command and Controlobserved in 3 of 4 tracked threats
  • T1489 Service Stop — Impactobserved in 3 of 4 tracked threats
  • T1490 Inhibit System Recovery — Impactobserved in 3 of 4 tracked threats
  • T1003.001 LSASS Memory — Credential Accessobserved in 2 of 4 tracked threats

Tracked threats