CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Payouts King Takes Aim at the Ransomware Throne

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6253

As cited

Copy frozen at (site build).

ransomware

Payouts King Takes Aim at the Ransomware Throne

Payouts King, an emerging ransomware group linked to former BlackBasta affiliates, employs sophisticated encryption using 4,096-bit RSA and 256-bit AES-CTR alongside advanced evasion techniques such as stack-based string obfuscation and direct system calls to bypass endpoint detection and response (EDR) tools. The group targets organizations through spam bombing combined with phishing and vishing, leveraging legitimate tools like Microsoft Teams and Quick Assist to establish initial access. Payouts King implements selective file encryption, terminates security processes by checksum matching, and establishes persistence via scheduled tasks while clearing forensic evidence.

Why it matters: Organizations and security teams face active campaigns from Payouts King since April 2025 using proven social engineering tactics; practitioners should enforce multifactor authentication (MFA), train users to recognize fake tech support scams, and monitor for anomalous Quick Assist usage, while updating detection signatures to identify the specific obfuscation and system call patterns described.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

Payouts King Takes Aim at the Ransomware Throne

Payouts King, an emerging ransomware group linked to former BlackBasta affiliates, employs sophisticated encryption using 4,096-bit RSA and 256-bit AES-CTR alongside advanced evasion techniques such as stack-based string obfuscation and direct system calls to bypass endpoint detection and response (EDR) tools. The group targets organizations through spam bombing combined with phishing and vishing, leveraging legitimate tools like Microsoft Teams and Quick Assist to establish initial access. Payouts King implements selective file encryption, terminates security processes by checksum matching, and establishes persistence via scheduled tasks while clearing forensic evidence.

Why it matters: Organizations and security teams face active campaigns from Payouts King since April 2025 using proven social engineering tactics; practitioners should enforce multifactor authentication (MFA), train users to recognize fake tech support scams, and monitor for anomalous Quick Assist usage, while updating detection signatures to identify the specific obfuscation and system call patterns described.

VendorsMicrosoftOpenSSL
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary