Payload
Threat Actor
Payload ransomware group is a highly active, financially motivated threat actor that first emerged in February 2026. Operating primarily on a double-extortion model, they encrypt enterprise data and exfiltrate sensitive files, threatening to publish them on their dedicated Tor leak sites if the ransom is not paid.
Incidents Associated with this Threat
- March 23, 2026: Safety Provider, Carlysle Engineering Hit in Ransomware Attack
Malware Used by this Threat Actor
No malware identified for this threat actor.
