Payload — Ransomware Profile
Payload is a ransomware group that emerged in early 2026, using Babuk-derived source code targeting both Windows and ESXi systems with cross-platform double-extortion attacks against healthcare, energy, real estate, and agriculture sectors, claiming 12 victims across seven countries within hours of launching its leak site.Tools & malware
- Payload Ransomware Ransomware
Recent claimed victims
- Qualiflex Datacenter | HWZ-Studiengnge (fh-hwz.ch), myenb.ch, etc 2026-08-20
- Zara Investment Holding 2026-08-13
- Baya Technologies 2026-08-11
- Stücheli Architekten 2026-08-11
- B&B Hydraulik 2026-08-11
- Hans & Jos. Kronenberg GmbH 2026-08-03
- CKR Consulting Engineers 2026-07-19
- Roofinox 2026-07-10
- The commune of Castries 2026-07-09
- ENB Versich 2026-07-05
- Vela Film S.r.l. 2026-07-05
- Tofutown 2026-07-02
- Villea Hotels in AttanaHo 2026-06-29
- Software Arge 2026-06-26
- Clínica La Sabana 2026-06-26
- Mosaic Partners 2026-06-26
- ENB Versicherungen | myenb.ch 2026-06-20
- Qualiflex Solutions | qualiflex.solutions 2026-06-20
- Preferred Properties 2026-06-20
- Editora Irmãos Vitale 2026-06-20
- SPORTON International Inc. 2026-06-16
- MyIPO 2026-06-13
- Hansoll Textile in Vietnam 2026-06-08
- Villea Hotels in AttanaHotels 2026-06-08
- Plaza Lama 2026-06-08
Vendor research
- Payload (Threat Group Profile) Halcyon