Payload — Ransomware Profile
Payload is a ransomware group that emerged in early 2026, using Babuk-derived source code targeting both Windows and ESXi systems with cross-platform double-extortion attacks against healthcare, energy, real estate, and agriculture sectors, claiming 12 victims across seven countries within hours of launching its leak site.Recent claimed victims
- Hans & Jos. Kronenberg GmbH 2026-08-03
- CKR Consulting Engineers 2026-07-19
- Roofinox 2026-07-10
- The commune of Castries 2026-07-09
- Vela Film S.r.l. 2026-07-05
- ENB Versich 2026-07-05
- Tofutown 2026-07-02
- Villea Hotels in AttanaHo 2026-06-29
- A 2026-06-26
- Software Arge 2026-06-26
- Clínica La Sabana 2026-06-26
- Mosaic Partners 2026-06-26
- ENB Versicherungen | myenb.ch 2026-06-20
- Preferred Properties 2026-06-20
- Editora Irmãos Vitale 2026-06-20
- Qualiflex Solutions | qualiflex.solutions 2026-06-20
- SPORTON International Inc. 2026-06-16
- MyIPO 2026-06-13
- Villea Hotels in AttanaHotels 2026-06-08
- Hansoll Textile in Vietnam 2026-06-08
- Plaza Lama 2026-06-08
- Robinsons 2026-05-21
- Internal Medicine and Pediatrics of Cullman 2026-05-21
- A-Sonic Logistic Solutions 2026-05-21
- G Theodor Freese 2026-05-21