Threat reportRansomwareTL-2026-1917
GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting Business Managers: 351 Victims Across 334 Organizations
GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting (TL-2026-1917), also tracked as Campaign targeting managers ThreatLabz, is a high-severity ransomware operation, first published 2026-08-06. It is attributed to GOLD ENCOUNTER with high confidence, affects Microsoft Windows 10/11, references 2 CVEs (CVE-2025-26399, CVE-2025-7775), maps to 25 MITRE ATT&CK techniques (T1003, T1005, T1021), and is covered by 9 detection rules and 27 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 2Referenced vulnerabilities
- Techniques
- 25MITRE ATT&CK
- Actors
- 1GOLD ENCOUNTER
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 27Indicators of compromise
Key facts for TL-2026-1917
- Threat ID
- TL-2026-1917
- Also known as
- Campaign targeting managers ThreatLabz, Former Black Basta affiliate campaign, Edgecution campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- Last reviewed
- Attribution
- GOLD ENCOUNTER
- Attribution confidence
- HIGH
- Motivation
- FINANCIAL
- Target sectors
- manufacturing, information technology, industrial, health, construction, agriculture, financial services, professional services
- Target regions
- North America, 155 - Western Europe, Central Europe
- Detection rules
- 9
- Indicators of compromise
- 27
Malware and tooling in GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting
Malware and tooling: AdaptixC2, Black Basta - S1070, payoutsking
How GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting works
An active ransomware campaign by the GOLD ENCOUNTER threat cluster (Payouts King ransomware, former Black Basta affiliates) has compromised 351 victims across 334 organizations in a single observed month. 62% of victims held manager-level titles or higher in accounting/finance (17.7%), sales (17.4%), and operations (16.8%). The group uses a sophisticated multi-stage attack chain combining email bombing, Microsoft Teams vishing, remote management tool abuse (Quick Assist/Supremo), the Edgecution browser-extension backdoor, and QEMU-hidden virtual machines for covert post-exploitation, culminating in AES-256+RSA-4096 file encryption and double extortion.
In August 2026, Zscaler ThreatLabz published research detailing an active ransomware campaign that compromised 351 individuals across 334 organizations in a single observed month. The campaign is notable for its systematic targeting of employees with business privilege — managers and directors in accounting, finance, sales, and operations — rather than technical administrators. 62% of victims held manager-level titles or higher, with an average age of 46 (44% Generation X), concentrated in industrials (35.5%) and information technology (14.6%).
The campaign is attributed to the GOLD ENCOUNTER cybercriminal threat cluster, which operates the Payouts King ransomware (also tracked by Sophos as STAC4713). GOLD ENCOUNTER emerged in mid-2025 following the dissolution of the Black Basta ransomware group in February 2025, and Zscaler ThreatLabz assesses with high confidence that its operators are former Black Basta affiliates. The group explicitly operates as a direct-action extortion team rather than a RaaS program.
The attack chain is multi-layered. Initial access typically begins with email bombing — flooding a target's inbox with hundreds of spam messages — followed within minutes by a Microsoft Teams or phone call from an attacker impersonating internal IT support. The victim is instructed to launch Quick Assist (natively installed on Windows 11) or download Supremo Remote Desktop, granting the attacker remote control. This social engineering sequence has been observed completing in as little as 12 minutes between initial chat and malicious script execution, with chats across multiple targets initiated just 29 seconds apart, suggesting automation.
Once access is established, the attackers deploy a sophisticated toolset. The Edgecution backdoor uses a malicious Microsoft Edge browser extension running in a hidden headless Edge instance, communicating with C2 servers hosted on AWS CloudFront over WebSocket (wss://) connections. The extension abuses the Chrome Native Messaging API to escape the browser sandbox and execute arbitrary Python code, PowerShell commands, and shell commands on the host. For deeper persistence, GOLD ENCOUNTER deploys QEMU virtual machines under SYSTEM-level scheduled tasks (TPMProfiler), running Alpine Linux disk images that serve as covert reverse SSH tunnels via AdaptixC2 or OpenSSH. This approach renders post-exploitation activity invisible to host-based endpoint detection.
The group employs extensive defense evasion: Payouts King encryptor uses CRC-obfuscated command-line parameters, API resolution by FNV1 hash, direct system calls to bypass EDR hooks, and terminates 131 hardcoded AV/EDR process names. A BYOVD (Bring Your Own Vulnerable Driver) technique deploys the K7RKScan kernel driver to disable security products. DLL sideloading via ADNotificationManager.exe delivers the Havoc C2 framework. Post-encryption, volume shadow copies are deleted via vssadmin, Windows Event Logs are cleared, and the Recycle Bin is emptied.
Encryption uses AES-256 in CTR mode with RSA-4096 asymmetric key protection via statically linked OpenSSL. Files smaller than 10 MB are fully encrypted; larger files are partially encrypted (13 blocks) for speed. Encrypted files receive the .ZWIAAW extension. The ransom note readme_locker.txt (only written when the -note parameter is supplied) directs victims to a Tor-based data leak site and TOX encrypted chat. The group operates a staged publication model: countdown timer, sample data release ("proof"), and full publication, with additional harassment campaigns mass-emailing victim employees, clients, and business partners using harvested contact data.
Exfiltration is conducted via Rclone, WinSCP, and custom SFTP transfers to remote infrastructure. Lateral movement uses WinRM, SMB, and Impacket tooling. Active Directory reconnaissance via BloodHound.py, Kerbrute for username enumeration, and KrbRelayx for Kerberos relay attacks enable comprehensive credential harvesting including NTDS.dit, SAM, and SYSTEM hive theft via Volume Shadow Copy service.
MITRE ATT&CK techniques used in TL-2026-1917
Credential Access
T1003 OS Credential Dumping; T1110 Brute Force; T1539 Steal Web Session Cookie; T1552 Unsecured Credentials
Collection
Lateral Movement
T1021 Remote Services; T1570 Lateral Tool Transfer
Defense Evasion
T1027 Obfuscated Files or Information; T1140 Deobfuscate/Decode Files or Information; T1574 Hijack Execution Flow
Persistence
T1053 Scheduled Task/Job; T1543 Create or Modify System Process
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution
Discovery
T1069 Permission Groups Discovery; T1087 Account Discovery; T1135 Network Share Discovery; T1482 Domain Trust Discovery; T1518 Software Discovery
Initial Access
T1078 Valid Accounts; T1190 Exploit Public-Facing Application; T1566 Phishing
Privilege Escalation
T1548 Abuse Elevation Control Mechanism
defense-impairment
Affected products and versions in GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting
- Microsoft — Windows 10/11
Vulnerable versions: All versions with Quick Assist enabled - Microsoft — Microsoft Teams
Vulnerable versions: All versions - SolarWinds — Web Help Desk
Vulnerable versions: Versions prior to CVE-2025-26399 patch
Fixed in: Patched version - Citrix — NetScaler ADC / Gateway
Vulnerable versions: Versions prior to CVE-2025-7775 patch
Fixed in: Patched version - SonicWall — SSL VPN Appliances
Vulnerable versions: Multiple versions without MFA enforcement - Cisco — SSL VPN Appliances
Vulnerable versions: Multiple versions
Remediation for GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting
Patches
- Apply patches for CVE-2025-26399 (SolarWinds Web Help Desk)
- Apply patches for CVE-2025-7775 (CitrixBleed2 / NetScaler ADC)
Immediate actions
- Block known Payouts King C2 CloudFront WebSocket domains on perimeter proxies
- Disable Microsoft Quick Assist for non-IT support users via Group Policy or MDM
- Implement email bomb detection rules to trigger user notification and heightened IT support scrutiny
- Restrict Supremo Remote Desktop and other unauthorized RMM tools at the endpoint and network perimeter
- Audit for unauthorized QEMU installations and unexpected scheduled tasks running under SYSTEM account
- Block known threat-actor IP ranges (84.42.92.0/24, 84.42.94.0/24) at the perimeter
Workarounds
- Disable or restrict Microsoft Quick Assist via Group Policy for non-administrative users
- Enable MFA on all VPN appliances (SonicWall, Cisco SSL VPN)
- Train users to verify IT impersonation attempts via out-of-band communication
- Restrict Chrome Native Messaging to approved extensions only via policy
Longer-term hardening
- Implement out-of-band verification for all IT help desk requests involving remote access
- Deploy EDR with behavioral detection for QEMU, Chrome Native Messaging abuse, and direct syscall patterns
- Enforce Zero Trust architecture with strict remote access controls and continuous session verification
- Deploy AI-powered inline threat protection with Teams communication monitoring
- Implement application control policies to block unauthorized RMM tools
- Implement strict application allowlisting to prevent unauthorized binary execution
- Deploy network detection for reverse SSH tunnels and non-standard port forwarding
CVEs associated with GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting
Weaknesses (CWE) in GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting
Timeline of GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting
- Black Basta ransomware group emerged as a prolific RaaS operation, operating until February 2025
- Black Basta internal chat logs leaked; group dissolved; former affiliates regroup under new brands including Payouts King/Cactus
- Payouts King ransomware operation emerged, attributed with high confidence to former Black Basta affiliates
- ReliaQuest begins tracking Teams-based phishing activity consistent with the former Black Basta affiliate campaign
- GOLD ENCOUNTER/Payouts King begins naming victims on their Tor-based data leak site; 22 victims listed in first month
- Sophos STAC4713 campaign first observed: QEMU hidden VM deployment for covert post-exploitation by Payouts King / GOLD ENCOUNTER
- V. FRAAS (US manufacturing) compromised by Payouts King; 625 GB data exfiltrated and published on leak site
- STAC4713 observed exploiting CVE-2025-26399 (SolarWinds Web Help Desk); QEMU disk image switched from vault.db to bisrv.dll disguise
- STAC3725 first observed: attackers shift from QEMU to DLL sideloading (ADNotificationManager.exe → Havoc C2) and Cisco SSL VPN exploitation
- Del Monte Foods (US food manufacturing) compromised by Payouts King; 1.2 TB data exfiltrated and published on leak site
- ReliaQuest observes attackers refining open-web reconnaissance automation to improve target pool quality, removing lower-privilege roles
- Former Black Basta affiliate campaign peaks: 77% of attacks target senior leadership (up from 59% in Jan-Feb); 32% of all Teams phishing since May 2025 occurs in this month alone
- Zscaler ThreatLabz publishes Edgecution analysis: malicious Edge browser extension using Chrome Native Messaging API for sandbox escape; C2 via AWS CloudFront WebSocket infrastructure
- Zscaler ThreatLabz publishes research on manager-targeting ransomware campaign: 351 victims across 334 organizations in one month; 62% manager-level victims
Sources cited for GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting
- Ransomware Moves up the Org Chart: Managers Are Prime Targets
- Are Former Black Basta Affiliates Automating Executive Targeting?
- Payouts King Takes Aim at the Ransomware Throne
- Edgecution: Payouts King IAB Deploys Malicious Edge Extension Backdoor
- QEMU Abused to Evade Detection and Enable Ransomware Delivery
- GOLD ENCOUNTER Threat Profile
- Payouts King Ransomware Uses QEMU VMs to Bypass Endpoint Security
- Threat Actor Deep Dive: Payouts King
- Black Basta's Playbook Lives On as Former Affiliates Launch Teams Phishing Attacks
- Payouts King Ransomware Evades EDR with Obfuscation and Direct System Calls
Detection coverage for TL-2026-1917
As of 2026-08-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1917 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.