Skip to content

Payload

Payload is a ransomware operation and associated Windows ransomware family first publicly observed in February 2026.

Profile source: Mallory opens in a new tab

Payload

Family profile

Payload is a ransomware operation and associated Windows ransomware family first publicly observed in February 2026. It emerged rapidly as a new extortion actor, advertising victims on a leak site within weeks of first appearance and showing a geographically broad victim set with notable activity affecting organizations in Egypt and the wider MENA region, alongside victims in Europe, Asia, and the Americas. Reported targeting spans public sector, healthcare, manufacturing, logistics, real estate, hospitality, technology, financial services, professional services, retail, and other commercial organizations, indicating largely opportunistic victimology rather than a narrowly specialized sector focus.

The group is commonly referred to as Payload and is also seen as payload_ransomware. It operates in the broader ransomware-as-a-service ecosystem and has been discussed alongside other active 2026 ransomware brands such as DragonForce, Play, Nova, and Akira as part of a fragmented criminal market characterized by affiliate mobility and shared operating patterns.

Technically, Payload deploys a Windows PE ransomware payload that encrypts files using ChaCha20 with per-file Curve25519 ECDH-derived key material, appends a dedicated Payload extension to encrypted files, and drops ransom notes for victim communication and recovery instructions. The malware has been described as comparatively mature in implementation, supporting parallelized encryption and configurable execution through numerous command-line options that control targeting, logging, mutex behavior, ransom note handling, self-deletion, process and service termination, network share encryption, and anti-detection features.

Observed defensive evasion and impact behavior includes patching Event Tracing for Windows functions to reduce telemetry, deleting Volume Shadow Copies to inhibit restoration, clearing Windows Event Logs, terminating processes and services that may lock files, and encrypting network-accessible data. These behaviors align with common late-stage ransomware tradecraft focused on maximizing operational disruption, accelerating encryption, and reducing recovery options. Payload has also been associated with data theft and leak-site publication, consistent with double-extortion operations in which encryption is paired with threatened public release of stolen information.

No high-confidence public attribution to a specific nation state is currently available. Available reporting supports classification of Payload as a financially motivated cybercriminal ransomware actor rather than a state-directed intrusion set.

Operational record

1
Indicators
1
YARA rules
2
Ransom notes
2
Leak sites
2 available

Published indicators

Sha256

1 total
  • bed8d1752a12e5681412efbb8283910857f7c5c431c2d73f9bbc5b379047a316

Recent claims

MITRE ATT&CK

Payload in ATT&CK

19 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.