Threat reportRansomwareTL-2026-1917

GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting Business Managers: 351 Victims Across 334 Organizations

highACTIVE

GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting (TL-2026-1917), also tracked as Campaign targeting managers ThreatLabz, is a high-severity ransomware operation, first published 2026-08-06. It is attributed to GOLD ENCOUNTER with high confidence, affects Microsoft Windows 10/11, references 2 CVEs (CVE-2025-26399, CVE-2025-7775), maps to 25 MITRE ATT&CK techniques (T1003, T1005, T1021), and is covered by 9 detection rules and 27 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
2Referenced vulnerabilities
Techniques
25MITRE ATT&CK
Actors
1GOLD ENCOUNTER
Detection rules
9SPL · KQL · Sigma
IOCs
27Indicators of compromise

Key facts for TL-2026-1917

Threat ID
TL-2026-1917
Also known as
Campaign targeting managers ThreatLabz, Former Black Basta affiliate campaign, Edgecution campaign
Severity
HIGH
Status
ACTIVE
Category
RANSOMWARE
First published
Last reviewed
Attribution
GOLD ENCOUNTER
Attribution confidence
HIGH
Motivation
FINANCIAL
Target sectors
manufacturing, information technology, industrial, health, construction, agriculture, financial services, professional services
Target regions
North America, 155 - Western Europe, Central Europe
Detection rules
9
Indicators of compromise
27

Malware and tooling in GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting

Malware and tooling: AdaptixC2, Black Basta - S1070, payoutsking

How GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting works

An active ransomware campaign by the GOLD ENCOUNTER threat cluster (Payouts King ransomware, former Black Basta affiliates) has compromised 351 victims across 334 organizations in a single observed month. 62% of victims held manager-level titles or higher in accounting/finance (17.7%), sales (17.4%), and operations (16.8%). The group uses a sophisticated multi-stage attack chain combining email bombing, Microsoft Teams vishing, remote management tool abuse (Quick Assist/Supremo), the Edgecution browser-extension backdoor, and QEMU-hidden virtual machines for covert post-exploitation, culminating in AES-256+RSA-4096 file encryption and double extortion.

In August 2026, Zscaler ThreatLabz published research detailing an active ransomware campaign that compromised 351 individuals across 334 organizations in a single observed month. The campaign is notable for its systematic targeting of employees with business privilege — managers and directors in accounting, finance, sales, and operations — rather than technical administrators. 62% of victims held manager-level titles or higher, with an average age of 46 (44% Generation X), concentrated in industrials (35.5%) and information technology (14.6%).

The campaign is attributed to the GOLD ENCOUNTER cybercriminal threat cluster, which operates the Payouts King ransomware (also tracked by Sophos as STAC4713). GOLD ENCOUNTER emerged in mid-2025 following the dissolution of the Black Basta ransomware group in February 2025, and Zscaler ThreatLabz assesses with high confidence that its operators are former Black Basta affiliates. The group explicitly operates as a direct-action extortion team rather than a RaaS program.

The attack chain is multi-layered. Initial access typically begins with email bombing — flooding a target's inbox with hundreds of spam messages — followed within minutes by a Microsoft Teams or phone call from an attacker impersonating internal IT support. The victim is instructed to launch Quick Assist (natively installed on Windows 11) or download Supremo Remote Desktop, granting the attacker remote control. This social engineering sequence has been observed completing in as little as 12 minutes between initial chat and malicious script execution, with chats across multiple targets initiated just 29 seconds apart, suggesting automation.

Once access is established, the attackers deploy a sophisticated toolset. The Edgecution backdoor uses a malicious Microsoft Edge browser extension running in a hidden headless Edge instance, communicating with C2 servers hosted on AWS CloudFront over WebSocket (wss://) connections. The extension abuses the Chrome Native Messaging API to escape the browser sandbox and execute arbitrary Python code, PowerShell commands, and shell commands on the host. For deeper persistence, GOLD ENCOUNTER deploys QEMU virtual machines under SYSTEM-level scheduled tasks (TPMProfiler), running Alpine Linux disk images that serve as covert reverse SSH tunnels via AdaptixC2 or OpenSSH. This approach renders post-exploitation activity invisible to host-based endpoint detection.

The group employs extensive defense evasion: Payouts King encryptor uses CRC-obfuscated command-line parameters, API resolution by FNV1 hash, direct system calls to bypass EDR hooks, and terminates 131 hardcoded AV/EDR process names. A BYOVD (Bring Your Own Vulnerable Driver) technique deploys the K7RKScan kernel driver to disable security products. DLL sideloading via ADNotificationManager.exe delivers the Havoc C2 framework. Post-encryption, volume shadow copies are deleted via vssadmin, Windows Event Logs are cleared, and the Recycle Bin is emptied.

Encryption uses AES-256 in CTR mode with RSA-4096 asymmetric key protection via statically linked OpenSSL. Files smaller than 10 MB are fully encrypted; larger files are partially encrypted (13 blocks) for speed. Encrypted files receive the .ZWIAAW extension. The ransom note readme_locker.txt (only written when the -note parameter is supplied) directs victims to a Tor-based data leak site and TOX encrypted chat. The group operates a staged publication model: countdown timer, sample data release ("proof"), and full publication, with additional harassment campaigns mass-emailing victim employees, clients, and business partners using harvested contact data.

Exfiltration is conducted via Rclone, WinSCP, and custom SFTP transfers to remote infrastructure. Lateral movement uses WinRM, SMB, and Impacket tooling. Active Directory reconnaissance via BloodHound.py, Kerbrute for username enumeration, and KrbRelayx for Kerberos relay attacks enable comprehensive credential harvesting including NTDS.dit, SAM, and SYSTEM hive theft via Volume Shadow Copy service.

MITRE ATT&CK techniques used in TL-2026-1917

Credential Access

T1003 OS Credential Dumping; T1110 Brute Force; T1539 Steal Web Session Cookie; T1552 Unsecured Credentials

Collection

T1005 Data from Local System

Lateral Movement

T1021 Remote Services; T1570 Lateral Tool Transfer

Defense Evasion

T1027 Obfuscated Files or Information; T1140 Deobfuscate/Decode Files or Information; T1574 Hijack Execution Flow

Persistence

T1053 Scheduled Task/Job; T1543 Create or Modify System Process

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Discovery

T1069 Permission Groups Discovery; T1087 Account Discovery; T1135 Network Share Discovery; T1482 Domain Trust Discovery; T1518 Software Discovery

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application; T1566 Phishing

Privilege Escalation

T1548 Abuse Elevation Control Mechanism

defense-impairment

T1553 Subvert Trust Controls; T1685 Disable or Modify Tools

Affected products and versions in GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting

  • Microsoft — Windows 10/11
    Vulnerable versions: All versions with Quick Assist enabled
  • Microsoft — Microsoft Teams
    Vulnerable versions: All versions
  • SolarWinds — Web Help Desk
    Vulnerable versions: Versions prior to CVE-2025-26399 patch
    Fixed in: Patched version
  • Citrix — NetScaler ADC / Gateway
    Vulnerable versions: Versions prior to CVE-2025-7775 patch
    Fixed in: Patched version
  • SonicWall — SSL VPN Appliances
    Vulnerable versions: Multiple versions without MFA enforcement
  • Cisco — SSL VPN Appliances
    Vulnerable versions: Multiple versions

Remediation for GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting

Patches

  • Apply patches for CVE-2025-26399 (SolarWinds Web Help Desk)
  • Apply patches for CVE-2025-7775 (CitrixBleed2 / NetScaler ADC)

Immediate actions

  • Block known Payouts King C2 CloudFront WebSocket domains on perimeter proxies
  • Disable Microsoft Quick Assist for non-IT support users via Group Policy or MDM
  • Implement email bomb detection rules to trigger user notification and heightened IT support scrutiny
  • Restrict Supremo Remote Desktop and other unauthorized RMM tools at the endpoint and network perimeter
  • Audit for unauthorized QEMU installations and unexpected scheduled tasks running under SYSTEM account
  • Block known threat-actor IP ranges (84.42.92.0/24, 84.42.94.0/24) at the perimeter

Workarounds

  • Disable or restrict Microsoft Quick Assist via Group Policy for non-administrative users
  • Enable MFA on all VPN appliances (SonicWall, Cisco SSL VPN)
  • Train users to verify IT impersonation attempts via out-of-band communication
  • Restrict Chrome Native Messaging to approved extensions only via policy

Longer-term hardening

  • Implement out-of-band verification for all IT help desk requests involving remote access
  • Deploy EDR with behavioral detection for QEMU, Chrome Native Messaging abuse, and direct syscall patterns
  • Enforce Zero Trust architecture with strict remote access controls and continuous session verification
  • Deploy AI-powered inline threat protection with Teams communication monitoring
  • Implement application control policies to block unauthorized RMM tools
  • Implement strict application allowlisting to prevent unauthorized binary execution
  • Deploy network detection for reverse SSH tunnels and non-standard port forwarding

CVEs associated with GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting

CVE-2025-26399, CVE-2025-7775

Weaknesses (CWE) in GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting

CWE-287, CWE-306, CWE-522

Timeline of GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting

  • Black Basta ransomware group emerged as a prolific RaaS operation, operating until February 2025
  • Black Basta internal chat logs leaked; group dissolved; former affiliates regroup under new brands including Payouts King/Cactus
  • Payouts King ransomware operation emerged, attributed with high confidence to former Black Basta affiliates
  • ReliaQuest begins tracking Teams-based phishing activity consistent with the former Black Basta affiliate campaign
  • GOLD ENCOUNTER/Payouts King begins naming victims on their Tor-based data leak site; 22 victims listed in first month
  • Sophos STAC4713 campaign first observed: QEMU hidden VM deployment for covert post-exploitation by Payouts King / GOLD ENCOUNTER
  • V. FRAAS (US manufacturing) compromised by Payouts King; 625 GB data exfiltrated and published on leak site
  • STAC4713 observed exploiting CVE-2025-26399 (SolarWinds Web Help Desk); QEMU disk image switched from vault.db to bisrv.dll disguise
  • STAC3725 first observed: attackers shift from QEMU to DLL sideloading (ADNotificationManager.exe → Havoc C2) and Cisco SSL VPN exploitation
  • Del Monte Foods (US food manufacturing) compromised by Payouts King; 1.2 TB data exfiltrated and published on leak site
  • ReliaQuest observes attackers refining open-web reconnaissance automation to improve target pool quality, removing lower-privilege roles
  • Former Black Basta affiliate campaign peaks: 77% of attacks target senior leadership (up from 59% in Jan-Feb); 32% of all Teams phishing since May 2025 occurs in this month alone
  • Zscaler ThreatLabz publishes Edgecution analysis: malicious Edge browser extension using Chrome Native Messaging API for sandbox escape; C2 via AWS CloudFront WebSocket infrastructure
  • Zscaler ThreatLabz publishes research on manager-targeting ransomware campaign: 351 victims across 334 organizations in one month; 62% manager-level victims

Sources cited for GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting

Detection coverage for TL-2026-1917

As of 2026-08-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1917 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
27 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats