GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting Business Managers: 351 Victims Across 334 Organizations — Threadlinqs Intelligence
As of 2026-08-06, GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting Business Managers: 351 Victims Across 334 Organizations is a high-severity ransomware threat attributed to GOLD ENCOUNTER, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 27 indicators of compromise.
Threat ID: TL-2026-1917 · Severity: HIGH · Status: ACTIVE · Category: RANSOMWARE
Attribution: GOLD ENCOUNTER · FINANCIAL
An active ransomware campaign by the GOLD ENCOUNTER threat cluster (Payouts King ransomware, former Black Basta affiliates) has compromised 351 victims across 334 organizations in a single observed
In August 2026, Zscaler ThreatLabz published research detailing an active ransomware campaign that compromised 351 individuals across 334 organizations in a single observed month. The campaign is notable for its systematic targeting of employees with business privilege — managers and directors in accounting, finance, sales, and operations — rather than technical administrators. 62% of victims held manager-level titles or higher, with an average age of 46 (44% Generation X), concentrated in industrials (35.5%) and information technology (14.6%).
The campaign is attributed to the GOLD ENCOUNTER cybercriminal threat cluster, which operates the Payouts King ransomware (also tracked by Sophos as STAC4713). GOLD ENCOUNTER emerged in mid-2025 following the dissolution of the Black Basta ransomware group in February 2025, and Zscaler ThreatLabz assesses with high confidence that its operators are former Black Basta affiliates. The group explicitly operates as a direct-action extortion team rather than a RaaS program.
The attack chain is multi-layered. Initial access typically begins with email bombing — flooding a target's inbox with hundreds of spam messages — followed within minutes by a Microsoft Teams or phone call from an attacker impersonating internal IT support. The victim is instructed to launch Quick Assist (natively installed on Windows 11) or download Supremo Remote Desktop, granting the attacker remote control. This social engineering sequence has been observed completing in as little as 12 minutes between initial chat and malicious script execution, with chats across multiple targets initiated just 29 seconds apart, suggesting automation.
Once access is established, the attackers deploy a sophisticated toolset. The Edgecution backdoor uses a malicious Microsoft Edge browser extension running in a hidden headless Edge instance, communicating with C2 servers hosted on AWS CloudFront over WebSocket (wss://) connections. The extension abuses the Chrome Native Messaging API to escape the browser sandbox and execute arbitrary Python code, PowerShell commands, and shell commands on the host. For deeper persistence, GOLD ENCOUNTER deploys QEMU virtual machines under SYSTEM-level scheduled tasks (TPMProfiler), running Alpine Linux disk images that serve as covert reverse SSH tunnels via AdaptixC2 or OpenSSH. This approach renders post-exploitation activity invisible to host-based endpoint detection.
The group employs extensive defense evasion: Payouts King encryptor uses CRC-obfuscated command-line parameters, API resolution by FNV1 hash, direct system calls to bypass EDR hooks, and terminates 131 hardcoded AV/EDR process names. A BYOVD (Bring Your Own Vulnerable Driver) technique deploys the K7RKScan kernel driver to disable security products. DLL sideloading via ADNotificationManager.exe delivers the Havoc C2 framework. Post-encryption, volume shadow copies are deleted via vssadmin, Windows Event Logs are cleared, and the Recycle Bin is emptied.
Encryption uses AES-256 in CTR mode with RSA-4096 asymmetric key protection via statically linked OpenSSL. Files smaller than 10 MB are fully encrypted; larger files are partially encrypted (13 blocks) for speed. Encrypted files receive the .ZWIAAW extension. The ransom note readme_locker.txt (only written when the -note parameter is supplied) directs victims to a Tor-based data leak site and TOX encrypted chat. The group operates a staged publication model: countdown timer, sample data release ("proof"), and full publication, with additional harassment campaigns mass-emailing victim employees, clients, and business partners using harvested contact data.
Exfiltration is conducted via Rclone, WinSCP, and custom SFTP transfers to remote infrastructure. Lateral movement uses WinRM, SMB, and Impacket tooling. Active Directory reconnaissance via BloodHound.py, Kerbrute for username enumeration, and KrbRelayx for Kerberos relay attacks enable comprehensive credential harvesting includin
Weaknesses (CWE)
CWE-287, CWE-306, CWE-522
Target sectors: manufacturing, information technology, industrial, health, construction, agriculture, financial services, professional services
Target regions: North America, 155 - Western Europe, Central Europe
Detections & IOCs
As of 2026-08-08, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 27 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, HIGH, threat intelligence, cybersecurity, CVE-2025-26399, CVE-2025-7775, T1566, T1190, T1078, T1059, T1204, T1053, T1543, T1548, T1562, T1574