PA

payload

Known ransomware group ACTIVE
Currently active

Payload is a ransomware group that emerged in early 2026, using Babuk-derived source code targeting both Windows and ESXi systems with cross-platform double-extortion attacks against healthcare, energy, real estate, and agriculture sectors, claiming 12 victims across seven countries within hours of launching its leak site.

9

Total Claims

1

Critical

Records Claimed

8

Industries Hit

Active span: Apr 16, 2026 – May 21, 2026 · 9 organizations targeted

Currently active
Activity 6.2 Severity 3.3 Sectors 7.3 Tooling 2.2

Actor Threat Profile

Activity Timeline

Peak: Apr 2026 (7)
Apr 2026
LessMore
May 2026

Share this profile

Shareable intel card for payload

Top Targeted Industries

Education 2
Healthcare 1
Public Sector 1
Business Services 1
Manufacturing 1
Agriculture and Food Production 1

Tradecraft & Infrastructure

0

Documented tools

5 / 11

MITRE tactics / techniques

2

Known leak sites

Full intelligence profile on ransomware.live →

Claims by payload

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.