# GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting Business Managers: 351 Victims Across 334 Organizations

> An active ransomware campaign by the GOLD ENCOUNTER threat cluster (Payouts King ransomware, former Black Basta affiliates) has compromised 351 victims across 334 organizations in a single observed month. 62% of victims held manager-level titles or higher in accounting/finance (17.7%), sales (17.4%), and operations (16.8%). The group uses a sophisticated multi-stage attack chain combining email bombing, Microsoft Teams vishing, remote management tool abuse (Quick Assist/Supremo), the Edgecution browser-extension backdoor, and QEMU-hidden virtual machines for covert post-exploitation, culminating in AES-256+RSA-4096 file encryption and double extortion.

- **Published:** 2026-08-06T17:30:00Z
- **Last reviewed:** 2026-08-06T17:30:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1917
- **ID:** TL-2026-1917
- **Severity:** HIGH
- **Category:** RANSOMWARE
- **Status:** ACTIVE
- **Actor:** GOLD ENCOUNTER
- **Detections:** 9 · **IOCs:** 27 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2025-26399, CVE-2025-7775

## Description

In August 2026, Zscaler ThreatLabz published research detailing an active ransomware campaign that compromised 351 individuals across 334 organizations in a single observed month. The campaign is notable for its systematic targeting of employees with business privilege — managers and directors in accounting, finance, sales, and operations — rather than technical administrators. 62% of victims held manager-level titles or higher, with an average age of 46 (44% Generation X), concentrated in industrials (35.5%) and information technology (14.6%).

The campaign is attributed to the GOLD ENCOUNTER cybercriminal threat cluster, which operates the Payouts King ransomware (also tracked by Sophos as STAC4713). GOLD ENCOUNTER emerged in mid-2025 following the dissolution of the Black Basta ransomware group in February 2025, and Zscaler ThreatLabz assesses with high confidence that its operators are former Black Basta affiliates. The group explicitly operates as a direct-action extortion team rather than a RaaS program.

The attack chain is multi-layered. Initial access typically begins with email bombing — flooding a target's inbox with hundreds of spam messages — followed within minutes by a Microsoft Teams or phone call from an attacker impersonating internal IT support. The victim is instructed to launch Quick Assist (natively installed on Windows 11) or download Supremo Remote Desktop, granting the attacker remote control. This social engineering sequence has been observed completing in as little as 12 minutes between initial chat and malicious script execution, with chats across multiple targets initiated just 29 seconds apart, suggesting automation.

Once access is established, the attackers deploy a sophisticated toolset. The Edgecution backdoor uses a malicious Microsoft Edge browser extension running in a hidden headless Edge instance, communicating with C2 servers hosted on AWS CloudFront over WebSocket (wss://) connections. The extension abuses the Chrome Native Messaging API to escape the browser sandbox and execute arbitrary Python code, PowerShell commands, and shell commands on the host. For deeper persistence, GOLD ENCOUNTER deploys QEMU virtual machines under SYSTEM-level scheduled tasks (TPMProfiler), running Alpine Linux disk images that serve as covert reverse SSH tunnels via AdaptixC2 or OpenSSH. This approach renders post-exploitation activity invisible to host-based endpoint detection.

The group employs extensive defense evasion: Payouts King encryptor uses CRC-obfuscated command-line parameters, API resolution by FNV1 hash, direct system calls to bypass EDR hooks, and terminates 131 hardcoded AV/EDR process names. A BYOVD (Bring Your Own Vulnerable Driver) technique deploys the K7RKScan kernel driver to disable security products. DLL sideloading via ADNotificationManager.exe delivers the Havoc C2 framework. Post-encryption, volume shadow copies are deleted via vssadmin, Windows Event Logs are cleared, and the Recycle Bin is emptied.

Encryption uses AES-256 in CTR mode with RSA-4096 asymmetric key protection via statically linked OpenSSL. Files smaller than 10 MB are fully encrypted; larger files are partially encrypted (13 blocks) for speed. Encrypted files receive the .ZWIAAW extension. The ransom note readme_locker.txt (only written when the -note parameter is supplied) directs victims to a Tor-based data leak site and TOX encrypted chat. The group operates a staged publication model: countdown timer, sample data release ("proof"), and full publication, with additional harassment campaigns mass-emailing victim employees, clients, and business partners using harvested contact data.

Exfiltration is conducted via Rclone, WinSCP, and custom SFTP transfers to remote infrastructure. Lateral movement uses WinRM, SMB, and Impacket tooling. Active Directory reconnaissance via BloodHound.py, Kerbrute for username enumeration, and KrbRelayx for Kerberos relay attacks enable comprehensive credential harvesting including NTDS.dit, SAM, and SYSTEM hive theft via Volume Shadow Copy service.

## MITRE ATT&CK

- T1566 Phishing
- T1190 Exploit Public-Facing Application
- T1078 Valid Accounts
- T1059 Command and Scripting Interpreter
- T1204 User Execution
- T1053 Scheduled Task/Job
- T1543 Create or Modify System Process
- T1548 Abuse Elevation Control Mechanism
- T1685 Disable or Modify Tools
- T1574 Hijack Execution Flow
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1553 Subvert Trust Controls
- T1003 OS Credential Dumping
- T1552 Unsecured Credentials
- T1110 Brute Force
- T1539 Steal Web Session Cookie
- T1087 Account Discovery
- T1069 Permission Groups Discovery
- T1518 Software Discovery
- T1135 Network Share Discovery
- T1482 Domain Trust Discovery
- T1021 Remote Services
- T1570 Lateral Tool Transfer
- T1005 Data from Local System

## Sources

- [Ransomware Moves up the Org Chart: Managers Are Prime Targets](https://www.zscaler.com/blogs/security-research/ransomware-moves-org-chart-managers-are-prime-targets)
- [Are Former Black Basta Affiliates Automating Executive Targeting?](https://reliaquest.com/blog/threat-spotlight-are-former-black-basta-affiliates-automating-executive-targeting/)
- [Payouts King Takes Aim at the Ransomware Throne](https://www.zscaler.com/blogs/security-research/payouts-king-takes-aim-ransomware-throne)
- [Edgecution: Payouts King IAB Deploys Malicious Edge Extension Backdoor](https://www.zscaler.com/blogs/security-research/payouts-king-ransomware-initial-access-broker-deploys-new-edgecution)
- [QEMU Abused to Evade Detection and Enable Ransomware Delivery](https://www.sophos.com/en-gb/blog/qemu-abused-to-evade-detection-and-enable-ransomware-delivery)
- [GOLD ENCOUNTER Threat Profile](https://www.sophos.com/en-us/threat-profiles/gold-encounter)
- [Payouts King Ransomware Uses QEMU VMs to Bypass Endpoint Security](https://www.bleepingcomputer.com/news/security/payouts-king-ransomware-uses-qemu-vms-to-bypass-endpoint-security/)
- [Threat Actor Deep Dive: Payouts King](https://www.surefirecyber.com/threat-actor-deep-dive-payouts-king/)
- [Black Basta's Playbook Lives On as Former Affiliates Launch Teams Phishing Attacks](https://cyberscoop.com/black-basta-affiliates-senior-executives-reliaquest/)
- [Payouts King Ransomware Evades EDR with Obfuscation and Direct System Calls](https://healsecurity.com/payouts-king-ransomware-evades-edr-with-obfuscation-and-direct-system-calls/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1917
