Payload

Threat Actor

Payload ransomware group is a highly active, financially motivated threat actor that first emerged in February 2026. Operating primarily on a double-extortion model, they encrypt enterprise data and exfiltrate sensitive files, threatening to publish them on their dedicated Tor leak sites if the ransom is not paid.

Incidents Associated with this Threat

Malware Used by this Threat Actor

No malware identified for this threat actor.