Threadlinqs IntelligenceStart free

Threat actorRussiaTracked since 2026-04

PayoutsKing

Also known as:Paykng CrewBlackBasta SuccessorStorm-2189

As of 2026-06-23, PayoutsKing is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 4 threats spanning malware, ransomware. Also known as Paykng Crew, BlackBasta Successor, Storm-2189. ATT&CK coverage spans 76 techniques across 15 tactics in 4 of 4 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1036.005 (Match Legitimate Resource Name or Location), T1059.001 (PowerShell).

Tracked threats
44 high
First seen
2026-04-16
Last seen
2026-06-23
ATT&CK techniques
76across 4 of 4 threats
Related CVEs
0None referenced
Attribution
RussiaNation or origin
Nation: Russia · 4 tracked threat(s) · Categories: MALWARE, RANSOMWARE

Activity timeline

PayoutsKing appears in 4 tracked threats between and ; the busiest month was 2026-04 with 3 reports.

ATT&CK techniques observed

76 techniques observed across 4 of 4 tracked threats · Initial Access (10), Discovery (8), Execution (8), Stealth (formerly Defense Evasion) (7), Command and Control (6), Collection (5)
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 4 of 4 tracked threats
  • T1036.005 Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion)observed in 4 of 4 tracked threats
  • T1059.001 PowerShell — Executionobserved in 4 of 4 tracked threats
  • T1071.001 Web Protocols — Command and Controlobserved in 4 of 4 tracked threats
  • T1204.002 User Execution: Malicious File — Executionobserved in 4 of 4 tracked threats
  • T1486 Data Encrypted for Impact — Impactobserved in 4 of 4 tracked threats
  • T1685 Disable or Modify Tools — Defense Impairmentobserved in 4 of 4 tracked threats
  • T1003.001 LSASS Memory — Credential Accessobserved in 3 of 4 tracked threats
  • T1021.001 Remote Desktop Protocol — Lateral Movementobserved in 3 of 4 tracked threats
  • T1021.002 SMB/Windows Admin Shares — Lateral Movementobserved in 3 of 4 tracked threats
  • T1059.003 Windows Command Shell — Executionobserved in 3 of 4 tracked threats
  • T1070.004 File Deletion — Stealth (formerly Defense Evasion)observed in 3 of 4 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 3 of 4 tracked threats
  • T1105 Ingress Tool Transfer — Command and Controlobserved in 3 of 4 tracked threats
  • T1489 Service Stop — Impactobserved in 3 of 4 tracked threats

Tracked threats