Beyond targets, the chat logs also highlighted Yanluowang’s use of the ransomware, PayloadBIN but also that attacks that involved it may potentially have been misattributed to another ransomware actor, Evil Corp.
Payload.bin
PayloadBIN is a Windows ransomware family associated with the Evil Corp cybercrime cluster and widely assessed as part of the same lineage as WastedLocker, Hades, and Phoenix Locker.
Profile source: Mallory opens in a new tabPayload.bin
Family profile
PayloadBIN is a Windows ransomware family associated with the Evil Corp cybercrime cluster and widely assessed as part of the same lineage as WastedLocker, Hades, and Phoenix Locker. It emerged as a continuation or rebranding of Phoenix Locker during Evil Corp’s broader pattern of renaming ransomware operations after U.S. sanctions complicated ransom payment facilitation and increased attribution pressure. Some reporting has also noted that attacks involving PayloadBIN may have been misattributed to other actors because of this deliberate rebranding strategy.
PayloadBIN encrypts victim files and is reported to append a distinctive new extension to encrypted data while dropping a ransom note identifying the PayloadBIN brand. Code-analysis reporting has linked it closely to Phoenix Locker and, by extension, to Hades and WastedLocker, citing substantial overlap in core functionality such as file enumeration and other implementation details. It has also been tied to the same broader tooling ecosystem used by Evil Corp, including packed samples associated with CryptOne in the relevant period.
Operationally, PayloadBIN fits the Evil Corp model of targeted enterprise ransomware intrusions rather than indiscriminate commodity deployment. Across this lineage, intrusions have involved initial access through phishing-delivered Dridex in earlier periods and later shifts toward SocGholish and Cobalt Strike to obscure attribution, with post-compromise activity including credential theft, reconnaissance, lateral movement, data exfiltration, and defense evasion before encryption. PayloadBIN has also been referenced in connection with Yanluowang-linked activity, indicating either shared use, code access, or attribution confusion around some incidents. The malware is primarily associated with financially motivated attacks against corporate environments across multiple sectors.
Capabilities
- Credential Theft
- Defense Evasion
- Exfiltration
- Lateral Movement
- Reconnaissance
Operational record
Reported operators
Threat actors
2 named in public reporting"...shifted to using ransomware variants such as ... Payload.bin."
MITRE ATT&CK