Ransomware Group intelligence
Payoutsking
ActiveTrack Payoutsking with 112 published victims and 1 known leak locations in a single intelligence view.
Overview
Payoutsking is tracked by Breach House as a ransomware group with 112 published victims.
United States is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Up checked 1h ago | payoutsgn7cy6uliwevdqspncjpfxpmzgirwl2au65la7rfs5x3qnbqd.onion |
Top Activity Sectors (15)
- Not identified 27
- Manufacturing / Engineering 24
- Communication / Marketing 9
- IT 8
- Construction / Real Estate 8
- Retail / E-commerce 6
- Healthcare / Pharma 6
- Hospitality / Food & Beverage / Tourism 4
- Energy 3
- Agriculture / Food 3
- Telecommunications 2
- Finance / Legal / Insurance 2
- Education 2
- Transportation / Travel / Logistics 2
- Services 2
Typical Attacks (8)
▼MITRE ATT&CK does not currently catalogue Payoutsking, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: payoutsking uses PowerShell scripts to execute malicious commands and deploy ransomware payloads across compromised systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: payoutsking persists by adding malicious entries to Windows Registry Run Keys to ensure recurring execution.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: payoutsking disables antivirus tools and security monitoring by terminating security processes and modifying system configurations.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: payoutsking deletes Volume Shadow Copies and backup directories using built-in Windows utilities to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: payoutsking moves laterally via SMB shares and mapped drives to access additional servers within the victim network.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1135 Network Share Discovery Discovery
What they do: payoutsking scans network shares to discover victim file structures and identify high-value targets for encryption.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1041 Exfiltration Over C2 Channel Exfiltration
What they do: payoutsking exfiltrates stolen data through encrypted C2 channels before deploying ransomware to enable double extortion.
What that means: Adversaries may steal data by exfiltrating it over an existing command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: payoutsking encrypts victim files using a custom ransomware engine, targeting business documents and backups for maximum disruption.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
readme_locker.txt
The files on the company's network have been encrypted, and significant amount of confidential data has been downloaded from it. To recover your files to the initial state and prevent disclosure of your sensitive information contact us as soon as possible via the TOX chat platform. - Download a TOX messaging client(https://tox.chat); - Create an account; - Add the following contact ID for futher negotiations: 74FB30F3FCC73D6B1BCE403238D082426F43D95F42CA25DF20CB278D91E8754B151651ED12DD In case you don't get in touch within 7 days, the exfiltrated data will be disclosed on our website: https://payoutsgn7cy6uliwevdqspncjpfxpmzgirwl2au65la7rfs5x3qnbqd.onion
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (112)
Search, filter and paginate the victim timeline for Payoutsking. Showing 101–112 of 112.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | BARIATRIX NUTRITION id21030 View details | Canada | Healthcare / Pharma | ||
|
[AI generated] Bariatix Nutrition is a company specializing in the field of medical nutrition therapy. The company develops and manufactures a wide range of high protein, low carb food products specifically designed to meet the dietary needs of bariatric patients. Their products are clinically tested and used by doctors to help patients lose weight and maintain a healthy lifestyle post-surgery. Their offerings include protein supplements, meal replacements, protein bars, and vitamin and mineral supplements, among others. |
|||||
| Ransomware | EvoluPharm id21029 View details | France | Healthcare / Pharma | ||
|
[AI generated] EvoluPharm is a leading player in the pharmaceutical sector in France. The company offers an innovative model providing solutions and services for pharmacists, including a wide range of generic and specialty pharmaceuticals. They aim to optimize and digitize pharmacies through various management tools, marketing solutions and training. They also emphasize environmentally friendly practices. |
|||||
| Ransomware | Silent Gliss Italia id21028 View details | Italy | Communication / Marketing | ||
|
[AI generated] Silent Gliss Italia is a branch of the global company, Silent Gliss, that specialises in the production and distribution of high-quality, innovative window treatments. The Switzerland-based company provides a wide range of products including curtain and blind systems. Silent Gliss Italia follows the parent company's commitment to exceptional Swiss quality, precision, and careful attention to detail in design. |
|||||
| Ransomware | Gateway Community id21027 View details | United States | Communication / Marketing | ||
|
[AI generated] Gateway Community, also known as Gateway Community Services, is a non-profit organization based in the U.S. Their mission is to provide comprehensive and effective services for individuals and families affected by addictive diseases, mental health disorders, and homelessness. They offer assistance through education, prevention, treatment, and housing programs. |
|||||
| Ransomware | Arch-Con Corporation id21026 View details | United States | Construction / Real Estate | ||
|
[AI generated] Arch-Con Corporation is a Texas-based general contractor offering construction services for multiple industries. Its expertise spans commercial, industrial, retail, healthcare, hospitality, community, and corporate interiors. Besides traditional construction services, Arch-Con offers pre-construction planning such as feasibility studies, value engineering options, and constructability reviews. |
|||||
| Ransomware | KOLBUS id21025 View details | Germany | Manufacturing / Engineering | ||
|
[AI generated] KOLBUS is a leading international manufacturer of machines and tools for bookbinders, print shops, and packaging companies. Headquartered in Germany, the company’s innovative solutions include packaging production lines, bookbinding systems, and luxury packaging. Additionally, KOLBUS offers spare parts, conversions, and upgrades services for its machinery. Established in 1775, the company has a rich history and significant experience in the printing and packaging industry. |
|||||
| Ransomware | CR Architecture + Design id21024 View details | United States | Construction / Real Estate | ||
|
[AI generated] CR Architecture + Design is a US-based company that specializes in providing architectural and design solutions. The firm delivers expertise across various sectors including housing, education, hospitality, and government. The team of architects, interior designers, and graphic designers work together, drawing on their different perspectives to create both functional and innovative spaces. They balance aesthetic concerns with practical requirements, ensuring successful project outcomes. |
|||||
| Ransomware | Institute of Culinary Education id21023 View details | United States | Education | ||
|
[AI generated] The Institute of Culinary Education (ICE) is a reputable culinary school based in New York City, USA. Founded in 1975, ICE offers a wide range of professional certificate programs in culinary arts, pastry & baking, hospitality management, and culinary technology, among others. The Institute is known for its modern facilities, experienced faculty, and strong industry connections. |
|||||
| Ransomware | Crenshaw Community Hospital id21022 View details | United States | Healthcare / Pharma | ||
|
[AI generated] Crenshaw Community Hospital is a medical facility based in Luverne, Alabama. Established in 1967, it offers a wide range of comprehensive health care services. In addition to an emergency department, the not-for-profit hospital operates outpatient clinics, laboratory and radiology services, and rehab facilities. The hospital remains committed to meeting the healthcare needs of Crenshaw County and the surrounding communities. |
|||||
| Ransomware | Rhea Vendors Group SpA id21021 View details | Italy | Communication / Marketing | ||
|
[AI generated] Rhea Vendors Group SpA is an Italy-based global company specializing in manufacturing vending machines for hot and cold drinks and snacks. Founded in 1960, the company utilizes advanced technology and innovative designs to deliver high-quality products. Their products range from custom-designed vending machines to fully automatic coffee machines. They cater to a broad range of industries, including offices, retail, and hospitality. |
|||||
| Ransomware | LTL id21020 View details | Spain | Other | ||
|
[AI generated] N/A |
|||||
| Ransomware | S****H id21019 View details | Germany | Other | — | |
|
No additional victim description available. |
|||||