Activity timeline
PayoutsKing appears in 4 tracked threats between and ; the busiest month was 2026-04 with 3 reports.
ATT&CK techniques observed
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 4 of 4 tracked threats
- T1036.005 Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion)observed in 4 of 4 tracked threats
- T1059.001 PowerShell — Executionobserved in 4 of 4 tracked threats
- T1071.001 Web Protocols — Command and Controlobserved in 4 of 4 tracked threats
- T1204.002 User Execution: Malicious File — Executionobserved in 4 of 4 tracked threats
- T1486 Data Encrypted for Impact — Impactobserved in 4 of 4 tracked threats
- T1685 Disable or Modify Tools — Defense Impairmentobserved in 4 of 4 tracked threats
- T1003.001 LSASS Memory — Credential Accessobserved in 3 of 4 tracked threats
- T1021.001 Remote Desktop Protocol — Lateral Movementobserved in 3 of 4 tracked threats
- T1021.002 SMB/Windows Admin Shares — Lateral Movementobserved in 3 of 4 tracked threats
- T1059.003 Windows Command Shell — Executionobserved in 3 of 4 tracked threats
- T1070.004 File Deletion — Stealth (formerly Defense Evasion)observed in 3 of 4 tracked threats
- T1082 System Information Discovery — Discoveryobserved in 3 of 4 tracked threats
- T1105 Ingress Tool Transfer — Command and Controlobserved in 3 of 4 tracked threats
- T1489 Service Stop — Impactobserved in 3 of 4 tracked threats
Tracked threats
- Edgecution: Payouts King Initial Access Broker Deploys Malicious Microsoft Edge Extension with Embedded Python BackdoorHIGH
- Payouts King Ransomware Uses QEMU Virtual Machines to Bypass EDR and Endpoint Security ControlsHIGH
- QEMU Virtualization Abuse for PayoutsKing Ransomware Delivery & EvasionHIGH
- Payouts King Ransomware — BlackBasta Successor Operation Targeting US Manufacturing, Healthcare, and Construction SectorsHIGH