Payouts King Ransomware — BlackBasta Successor Operation Targeting US Manufacturing, Healthcare, and Construction Sectors
Payouts King Ransomware (TL-2026-0378), also tracked as PayoutsKing, is a high-severity ransomware operation, first published 2026-04-16. It is attributed to Payouts King (Russia) with high confidence, affects Microsoft Windows Workstations and Servers, maps to 38 MITRE ATT&CK techniques (T1003.001, T1005, T1021.001), and is covered by 9 detection rules and 24 indicators of compromise.
Key facts for TL-2026-0378
- Threat ID
- TL-2026-0378
- Also known as
- PayoutsKing, Payouts King Ransomware, BlackBasta successor operation
- Severity
- HIGH
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- 2026-04-16
- Last reviewed
- 2026-04-16
- Attribution
- Payouts King
- Attribution confidence
- HIGH
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- manufacturing, healthcare, construction, engineering, behavioral-health, rehabilitation-services
- Target regions
- North America, United States
- Detection rules
- 9
- Indicators of compromise
- 24
Malware and tooling in Payouts King Ransomware
Malware and tooling: PayoutsKing Encryptor, payoutsking, AnyDesk, BloodHound / SharpHound, Cobalt Strike, MEGAsync, Mimikatz, NetSupport Manager, Rclone - S1040, ScreenConnect, WinSCP
Payouts King is an active double-extortion ransomware operation that emerged in April 2025 and has been attributed with high confidence by Zscaler ThreatLabz to former BlackBasta affiliates following BlackBasta's February 2025 disbandment. The group reuses BlackBasta-era TTPs — email bombing, Microsoft Teams IT-support impersonation, and Quick Assist remote-control abuse for initial access — then performs hands-on-keyboard lateral movement, broad data theft, and selective file encryption using RSA-4096 + AES-256-CTR. As of April 2026 the group has publicly named 60+ victims with approximately 18.7 TB of claimed exfiltrated data, concentrated in US manufacturing, healthcare, and construction organizations.
How Payouts King Ransomware works
Payouts King is a ransomware-and-extortion operation first observed in April 2025 following the February 2025 collapse of the BlackBasta cartel, whose internal Matrix chat logs were leaked by the handle 'ExploitWhispers' in mid-February 2025. Zscaler ThreatLabz's April 2026 research attributes Payouts King to former BlackBasta affiliates with high confidence based on shared tradecraft, reused tooling, overlapping victimology, and near-identical social-engineering playbooks.
Initial access is achieved through a distinctive social-engineering chain directly inherited from BlackBasta. Operators first conduct 'email bombing' against a target employee — subscribing the victim's corporate email to thousands of newsletter and marketing lists within minutes to produce a flood of legitimate-looking but overwhelming inbound mail. While the victim is distracted, the operator places a Microsoft Teams chat or call from an externally federated tenant configured with a display name that impersonates the organization's IT help-desk (e.g., 'IT Support', 'Help Desk', 'Security Operations'). Posing as IT, the operator walks the victim through opening Windows Quick Assist (quickassist.exe) and accepting a remote-control session, at which point the attacker has an interactive foothold on a domain-joined workstation.
From the Quick Assist foothold, operators drop second-stage tooling — typically AnyDesk, NetSupport Manager, or ScreenConnect for resilient remote access — alongside a Cobalt Strike beacon. Payouts King operators conduct credential access via LSASS memory dumping and Kerberoasting, enumerate Active Directory with BloodHound/SharpHound and native LOLBins (net.exe, nltest, dsquery), and pivot laterally via SMB admin shares, WMI, and RDP. Domain Admin compromise is typically achieved within hours.
Prior to encryption, operators stage large volumes of business data using rclone, MegaSync, WinSCP, and occasionally FileZilla, exfiltrating to attacker-controlled cloud endpoints. Selective encryption is then performed with a custom Windows PE-based encryptor that implements RSA-4096 envelope encryption of per-file AES-256-CTR keys — a direct evolution of the BlackBasta encryption scheme. Volume shadow copies are destroyed with vssadmin.exe and wbadmin.exe, backups are targeted where reachable, and Microsoft Defender is tampered with via registry keys and PowerShell cmdlets.
The group operates a Tor-hosted data-leak site ('payoutsking') where victims are named and countdown timers drive payment pressure. ransomware.live tracker first profiled the group in July 2025; BlackFog's February 2026 analysis and Zscaler ThreatLabz's April 2026 deep-dive confirm 60+ listed victims with approximately 18.7 TB of claimed exfiltrated data. Known named victims include rehabilitation clinics in Jacksonville, Florida (September 2025) and Prater Engineering Associates (February 2026, 2.5 TB claim). Sector targeting is concentrated in US manufacturing, healthcare (notably behavioral health and rehab), and construction/engineering firms — organizations typically characterized by tight operational uptime requirements and limited mature EDR coverage.
Defensive priorities: (1) restrict Microsoft Teams external federation and display-name spoofing via tenant-level policy; (2) disable or tightly constrain Quick Assist in enterprise environments, or alert on quickassist.exe execution; (3) monitor for email-bombing patterns (sudden spike in unique sender domains per mailbox); (4) alert on unsigned RMM binaries (AnyDesk, NetSupport, ScreenConnect) appearing on endpoints outside sanctioned deployments; (5) enforce tamper protection on Microsoft Defender and EDR; (6) monitor vssadmin/wbadmin destructive subcommands; (7) baseline rclone/MegaSync/WinSCP egress to unfamiliar cloud endpoints.
MITRE ATT&CK techniques used in TL-2026-0378
Credential Access
T1003.001 OS Credential Dumping: LSASS Memory; T1558.003 Steal or Forge Kerberos Tickets: Kerberoasting
Collection
T1005 Data from Local System; T1039 Data from Network Shared Drive; T1560 Archive Collected Data
Lateral Movement
T1021.001 Remote Services: Remote Desktop Protocol; T1021.002 Remote Services: SMB/Windows Admin Shares; T1570 Lateral Tool Transfer
Defense Evasion
T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1070.004 Indicator Removal: File Deletion
Execution
T1047 Windows Management Instrumentation; T1059.001 Command and Scripting Interpreter: PowerShell; T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1204.002 User Execution: Malicious File
Exfiltration
T1048 Exfiltration Over Alternative Protocol; T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1105 Ingress Tool Transfer
Initial Access
T1078.002 Valid Accounts: Domain Accounts; T1566 Phishing; T1566.004 Phishing: Spearphishing Voice
Discovery
T1083 File and Directory Discovery; T1087.002 Account Discovery: Domain Account; T1135 Network Share Discovery; T1482 Domain Trust Discovery
Privilege Escalation
T1134 Access Token Manipulation; T1548.002 Abuse Elevation Control Mechanism: Bypass User Account Control
command-and-control
Impact
T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery
Persistence
T1543.003 Create or Modify System Process: Windows Service
Resource Development
T1583 Acquire Infrastructure; T1583.001 Acquire Infrastructure: Domains; T1587.001 Develop Capabilities: Malware
Reconnaissance
T1589.002 Gather Victim Identity Information: Email Addresses
defense-impairment
Affected products and versions in Payouts King Ransomware
- Microsoft — Windows Workstations and Servers
Vulnerable versions: Windows 10; Windows 11; Windows Server 2016; Windows Server 2019; Windows Server 2022 - Microsoft — Microsoft Teams (federation configuration)
Vulnerable versions: Tenants with permissive external federation and anonymous chat enabled - Microsoft — Quick Assist (quickassist.exe)
Vulnerable versions: All currently shipping versions when enabled for non-IT users - VMware — ESXi Hypervisor
Vulnerable versions: ESXi 6.7 / 7.0 / 8.0 — targeted for VM encryption in some incidents
Remediation for Payouts King Ransomware
Patches
- No single CVE drives this operation — ensure Microsoft 365/Teams admin policies updated to latest hardening guidance (external access, anonymous meeting join disabled)
- Apply Microsoft security baselines for Windows 10/11 and Windows Server 2019/2022
- Ensure Active Directory is at current functional level with LAPS deployed
Immediate actions
- Restrict Microsoft Teams external federation to an allowlist of known partner tenants; disable anonymous external chat/call initiation
- Disable Windows Quick Assist (quickassist.exe) on enterprise endpoints or restrict via AppLocker/WDAC; alert on any quickassist.exe process start
- Block unsigned/unapproved RMM binaries (AnyDesk, NetSupport, ScreenConnect, TeamViewer) via EDR application control
- Enforce Microsoft Defender tamper protection and MFA on all privileged accounts; rotate Kerberos krbtgt twice if compromise suspected
- Deploy detections for vssadmin delete shadows and wbadmin delete catalog destructive subcommands
Workarounds
- If Quick Assist cannot be disabled, require help-desk remote sessions only via corporate RMM over ZTNA; train users that IT will never initiate a Teams call from an external tenant
- Block outbound connections to rclone/MegaSync/pCloud/Mega endpoints from user workstations at the egress proxy
- Implement honey-token accounts in AD to detect Kerberoasting attempts
Longer-term hardening
- Implement tiered administration (Tier 0/1/2) to contain Domain Admin compromise blast radius
- Deploy identity threat detection (ITDR) covering Kerberoasting, LSASS access, AS-REP roasting, and DCSync
- Roll out mail-flow rules that detect and quarantine email-bombing patterns (>N unique sender domains per mailbox per hour)
- Segment backup infrastructure off the production AD forest with immutable/air-gapped copies
- Run tabletop exercises covering Teams-vishing initial access and hands-on-keyboard ransomware response
Timeline of Payouts King Ransomware
- BlackBasta ransomware cartel operations effectively suspended after the 'ExploitWhispers' Matrix chat leak exposes internal affiliate communications; affiliates begin dispersing to new or rebranded operations.
- Payouts King ransomware operation emerges with first publicly listed victims on a newly stood-up Tor data-leak site ('payoutsking'), two months after the BlackBasta collapse.
- ransomware.live tracker publishes a dedicated group profile for Payouts King, cataloguing victim postings and initial TTP observations.
- Comparitech reports Payouts King attacks against multiple rehabilitation clinics in Jacksonville, Florida — first prominent healthcare-sector incident.
- BlackFog publishes a Cybersecurity 101 profile of Payouts King documenting double-extortion behaviour, leak-site operation, and sector targeting.
- Payouts King lists Prater Engineering Associates on its leak site and threatens to publish 2.5 TB of exfiltrated data — one of the group's largest individual-victim claims to date.
- Zscaler ThreatLabz publishes deep-dive research attributing Payouts King to former BlackBasta affiliates with high confidence based on shared tradecraft (email bombing + Teams + Quick Assist), reused tooling, and victimology overlap. 60+ total victims, ~18.7 TB claimed.
- Threadlinqs Intelligence documents threat TL-2026-0378 with full MITRE mapping, IOCs, detection coverage, and simulation profile.
- As of 2026-05-29, Payouts King remains a live, escalating threat: ransomware.live shows 100 named victims (up from 60 in April), the most recent posted May 13, 2026, and the leak site visited through 2026-05-30. No takedown, arrest, or disruption reported; TTPs (email-bombing + Teams + Quick Assist) unchanged.
Sources cited for Payouts King Ransomware
- Payouts King Takes Aim at the Ransomware Throne — Zscaler ThreatLabz (via Security Boulevard)
- ransomware.live — Payouts King group profile and victim tracker
- BlackFog — Payouts King ransomware profile
- Comparitech — Rehab Clinics in Jacksonville Targeted by New Ransomware Gang
- Dark Web Informer — Prater Engineering Associates victim post (2.5 TB claim)
- MITRE ATT&CK — T1566.004 Spearphishing Voice
- MITRE ATT&CK — T1219 Remote Access Software
- CISA StopRansomware — Ransomware Guide
Threats related to Payouts King Ransomware
- Payouts King Ransomware Uses QEMU Virtual Machines to Bypass EDR and Endpoint Security Controls
- QEMU Virtualization Abuse for PayoutsKing Ransomware Delivery & Evasion
- Conti Ransomware Malware Developer Oleksii Lytvynenko Pleads Guilty to Wire Fraud Conspiracy (DOJ, June 2026)
- Kyber Ransomware: Post-Quantum Hybrid Encryption Operation Targeting Windows & VMware ESXi
- DeadLock Ransomware Double-Extortion Attack on Diater (Spanish Biopharmaceutical Firm) Exposes Decade of Clinical/Pharmacovigilance Records
- SafePay Ransomware Abuses OneDrive Sync Client for Covert Data Exfiltration
Detection coverage for TL-2026-0378
As of 2026-04-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0378 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.