Payday
Payday is an active ransomware/extortion group tracked on ransomware.live from the victims it lists on its public leak site.
Payday is a financially motivated ransomware group known for double extortion.
Payday is a financially motivated cybercriminal ransomware group. They target organizations across various sectors, employing a double extortion model by exfiltrating data before encrypting files and threatening victims via a public leak site. Their core TTPs include data theft and file encryption, although specific tools are not detailed in the provided data. Defenders should focus on robust network segmentation, immutable offline backups, and anomaly-based behavioral detection to identify intrusion and exfiltration attempts.
Payday is an active ransomware/extortion group tracked on ransomware.live from the victims it lists on its public leak site.
The Payday group uses a double extortion tactic: after breaching the network, they exfiltrate data, encrypt files, and threaten victims by exposing them on a public leak site.
Defenders should focus on robust network segmentation, reliable offline backups, and anomaly-based behavioral detection to identify intrusion and exfiltration attempts.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.