Payouts King Ransomware — BlackBasta Successor Operation Targeting US Manufacturing, Healthcare, and Construction Sectors

Payouts King Ransomware (TL-2026-0378), also tracked as PayoutsKing, is a high-severity ransomware operation, first published 2026-04-16. It is attributed to Payouts King (Russia) with high confidence, affects Microsoft Windows Workstations and Servers, maps to 38 MITRE ATT&CK techniques (T1003.001, T1005, T1021.001), and is covered by 9 detection rules and 24 indicators of compromise.

Key facts for TL-2026-0378

Threat ID
TL-2026-0378
Also known as
PayoutsKing, Payouts King Ransomware, BlackBasta successor operation
Severity
HIGH
Status
ACTIVE
Category
RANSOMWARE
First published
2026-04-16
Last reviewed
2026-04-16
Attribution
Payouts King
Attribution confidence
HIGH
Nation-state nexus
Russia
Motivation
FINANCIAL
Target sectors
manufacturing, healthcare, construction, engineering, behavioral-health, rehabilitation-services
Target regions
North America, United States
Detection rules
9
Indicators of compromise
24

Malware and tooling in Payouts King Ransomware

Malware and tooling: PayoutsKing Encryptor, payoutsking, AnyDesk, BloodHound / SharpHound, Cobalt Strike, MEGAsync, Mimikatz, NetSupport Manager, Rclone - S1040, ScreenConnect, WinSCP

Payouts King is an active double-extortion ransomware operation that emerged in April 2025 and has been attributed with high confidence by Zscaler ThreatLabz to former BlackBasta affiliates following BlackBasta's February 2025 disbandment. The group reuses BlackBasta-era TTPs — email bombing, Microsoft Teams IT-support impersonation, and Quick Assist remote-control abuse for initial access — then performs hands-on-keyboard lateral movement, broad data theft, and selective file encryption using RSA-4096 + AES-256-CTR. As of April 2026 the group has publicly named 60+ victims with approximately 18.7 TB of claimed exfiltrated data, concentrated in US manufacturing, healthcare, and construction organizations.

How Payouts King Ransomware works

Payouts King is a ransomware-and-extortion operation first observed in April 2025 following the February 2025 collapse of the BlackBasta cartel, whose internal Matrix chat logs were leaked by the handle 'ExploitWhispers' in mid-February 2025. Zscaler ThreatLabz's April 2026 research attributes Payouts King to former BlackBasta affiliates with high confidence based on shared tradecraft, reused tooling, overlapping victimology, and near-identical social-engineering playbooks.

Initial access is achieved through a distinctive social-engineering chain directly inherited from BlackBasta. Operators first conduct 'email bombing' against a target employee — subscribing the victim's corporate email to thousands of newsletter and marketing lists within minutes to produce a flood of legitimate-looking but overwhelming inbound mail. While the victim is distracted, the operator places a Microsoft Teams chat or call from an externally federated tenant configured with a display name that impersonates the organization's IT help-desk (e.g., 'IT Support', 'Help Desk', 'Security Operations'). Posing as IT, the operator walks the victim through opening Windows Quick Assist (quickassist.exe) and accepting a remote-control session, at which point the attacker has an interactive foothold on a domain-joined workstation.

From the Quick Assist foothold, operators drop second-stage tooling — typically AnyDesk, NetSupport Manager, or ScreenConnect for resilient remote access — alongside a Cobalt Strike beacon. Payouts King operators conduct credential access via LSASS memory dumping and Kerberoasting, enumerate Active Directory with BloodHound/SharpHound and native LOLBins (net.exe, nltest, dsquery), and pivot laterally via SMB admin shares, WMI, and RDP. Domain Admin compromise is typically achieved within hours.

Prior to encryption, operators stage large volumes of business data using rclone, MegaSync, WinSCP, and occasionally FileZilla, exfiltrating to attacker-controlled cloud endpoints. Selective encryption is then performed with a custom Windows PE-based encryptor that implements RSA-4096 envelope encryption of per-file AES-256-CTR keys — a direct evolution of the BlackBasta encryption scheme. Volume shadow copies are destroyed with vssadmin.exe and wbadmin.exe, backups are targeted where reachable, and Microsoft Defender is tampered with via registry keys and PowerShell cmdlets.

The group operates a Tor-hosted data-leak site ('payoutsking') where victims are named and countdown timers drive payment pressure. ransomware.live tracker first profiled the group in July 2025; BlackFog's February 2026 analysis and Zscaler ThreatLabz's April 2026 deep-dive confirm 60+ listed victims with approximately 18.7 TB of claimed exfiltrated data. Known named victims include rehabilitation clinics in Jacksonville, Florida (September 2025) and Prater Engineering Associates (February 2026, 2.5 TB claim). Sector targeting is concentrated in US manufacturing, healthcare (notably behavioral health and rehab), and construction/engineering firms — organizations typically characterized by tight operational uptime requirements and limited mature EDR coverage.

Defensive priorities: (1) restrict Microsoft Teams external federation and display-name spoofing via tenant-level policy; (2) disable or tightly constrain Quick Assist in enterprise environments, or alert on quickassist.exe execution; (3) monitor for email-bombing patterns (sudden spike in unique sender domains per mailbox); (4) alert on unsigned RMM binaries (AnyDesk, NetSupport, ScreenConnect) appearing on endpoints outside sanctioned deployments; (5) enforce tamper protection on Microsoft Defender and EDR; (6) monitor vssadmin/wbadmin destructive subcommands; (7) baseline rclone/MegaSync/WinSCP egress to unfamiliar cloud endpoints.

MITRE ATT&CK techniques used in TL-2026-0378

Credential Access

T1003.001 OS Credential Dumping: LSASS Memory; T1558.003 Steal or Forge Kerberos Tickets: Kerberoasting

Collection

T1005 Data from Local System; T1039 Data from Network Shared Drive; T1560 Archive Collected Data

Lateral Movement

T1021.001 Remote Services: Remote Desktop Protocol; T1021.002 Remote Services: SMB/Windows Admin Shares; T1570 Lateral Tool Transfer

Defense Evasion

T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1070.004 Indicator Removal: File Deletion

Execution

T1047 Windows Management Instrumentation; T1059.001 Command and Scripting Interpreter: PowerShell; T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1204.002 User Execution: Malicious File

Exfiltration

T1048 Exfiltration Over Alternative Protocol; T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1105 Ingress Tool Transfer

Initial Access

T1078.002 Valid Accounts: Domain Accounts; T1566 Phishing; T1566.004 Phishing: Spearphishing Voice

Discovery

T1083 File and Directory Discovery; T1087.002 Account Discovery: Domain Account; T1135 Network Share Discovery; T1482 Domain Trust Discovery

Privilege Escalation

T1134 Access Token Manipulation; T1548.002 Abuse Elevation Control Mechanism: Bypass User Account Control

command-and-control

T1219 Remote Access Tools

Impact

T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery

Persistence

T1543.003 Create or Modify System Process: Windows Service

Resource Development

T1583 Acquire Infrastructure; T1583.001 Acquire Infrastructure: Domains; T1587.001 Develop Capabilities: Malware

Reconnaissance

T1589.002 Gather Victim Identity Information: Email Addresses

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Payouts King Ransomware

  • Microsoft — Windows Workstations and Servers
    Vulnerable versions: Windows 10; Windows 11; Windows Server 2016; Windows Server 2019; Windows Server 2022
  • Microsoft — Microsoft Teams (federation configuration)
    Vulnerable versions: Tenants with permissive external federation and anonymous chat enabled
  • Microsoft — Quick Assist (quickassist.exe)
    Vulnerable versions: All currently shipping versions when enabled for non-IT users
  • VMware — ESXi Hypervisor
    Vulnerable versions: ESXi 6.7 / 7.0 / 8.0 — targeted for VM encryption in some incidents

Remediation for Payouts King Ransomware

Patches

  • No single CVE drives this operation — ensure Microsoft 365/Teams admin policies updated to latest hardening guidance (external access, anonymous meeting join disabled)
  • Apply Microsoft security baselines for Windows 10/11 and Windows Server 2019/2022
  • Ensure Active Directory is at current functional level with LAPS deployed

Immediate actions

  • Restrict Microsoft Teams external federation to an allowlist of known partner tenants; disable anonymous external chat/call initiation
  • Disable Windows Quick Assist (quickassist.exe) on enterprise endpoints or restrict via AppLocker/WDAC; alert on any quickassist.exe process start
  • Block unsigned/unapproved RMM binaries (AnyDesk, NetSupport, ScreenConnect, TeamViewer) via EDR application control
  • Enforce Microsoft Defender tamper protection and MFA on all privileged accounts; rotate Kerberos krbtgt twice if compromise suspected
  • Deploy detections for vssadmin delete shadows and wbadmin delete catalog destructive subcommands

Workarounds

  • If Quick Assist cannot be disabled, require help-desk remote sessions only via corporate RMM over ZTNA; train users that IT will never initiate a Teams call from an external tenant
  • Block outbound connections to rclone/MegaSync/pCloud/Mega endpoints from user workstations at the egress proxy
  • Implement honey-token accounts in AD to detect Kerberoasting attempts

Longer-term hardening

  • Implement tiered administration (Tier 0/1/2) to contain Domain Admin compromise blast radius
  • Deploy identity threat detection (ITDR) covering Kerberoasting, LSASS access, AS-REP roasting, and DCSync
  • Roll out mail-flow rules that detect and quarantine email-bombing patterns (>N unique sender domains per mailbox per hour)
  • Segment backup infrastructure off the production AD forest with immutable/air-gapped copies
  • Run tabletop exercises covering Teams-vishing initial access and hands-on-keyboard ransomware response

Timeline of Payouts King Ransomware

  • BlackBasta ransomware cartel operations effectively suspended after the 'ExploitWhispers' Matrix chat leak exposes internal affiliate communications; affiliates begin dispersing to new or rebranded operations.
  • Payouts King ransomware operation emerges with first publicly listed victims on a newly stood-up Tor data-leak site ('payoutsking'), two months after the BlackBasta collapse.
  • ransomware.live tracker publishes a dedicated group profile for Payouts King, cataloguing victim postings and initial TTP observations.
  • Comparitech reports Payouts King attacks against multiple rehabilitation clinics in Jacksonville, Florida — first prominent healthcare-sector incident.
  • BlackFog publishes a Cybersecurity 101 profile of Payouts King documenting double-extortion behaviour, leak-site operation, and sector targeting.
  • Payouts King lists Prater Engineering Associates on its leak site and threatens to publish 2.5 TB of exfiltrated data — one of the group's largest individual-victim claims to date.
  • Zscaler ThreatLabz publishes deep-dive research attributing Payouts King to former BlackBasta affiliates with high confidence based on shared tradecraft (email bombing + Teams + Quick Assist), reused tooling, and victimology overlap. 60+ total victims, ~18.7 TB claimed.
  • Threadlinqs Intelligence documents threat TL-2026-0378 with full MITRE mapping, IOCs, detection coverage, and simulation profile.
  • As of 2026-05-29, Payouts King remains a live, escalating threat: ransomware.live shows 100 named victims (up from 60 in April), the most recent posted May 13, 2026, and the leak site visited through 2026-05-30. No takedown, arrest, or disruption reported; TTPs (email-bombing + Teams + Quick Assist) unchanged.

Sources cited for Payouts King Ransomware

Threats related to Payouts King Ransomware

Detection coverage for TL-2026-0378

As of 2026-04-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0378 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats