Payload is a Babuk-based ransomware group from early 2026 known for double-extortion attacks.
Analyst brief
Payload is a ransomware group that emerged in early 2026, using Babuk-derived source code to target both Windows and ESXi systems. The group conducts double-extortion attacks against sectors including healthcare, energy, manufacturing, and government defense across countries like Switzerland, Germany, Turkey, and Brazil. Key TTPs include Babuk-based encryption, data exfiltration, and pressure via a leak site. Defenders should focus on patch management for ESXi hypervisors, offline backups, and network segmentation.
payload
activecrime
Payload is a ransomware group that emerged in early 2026, using Babuk-derived source code targeting both Windows and ESXi systems with cross-platform double-extortion attacks against healthcare, energy, real estate, and agriculture sectors, claiming 12 victims across seven countries within hours of launching its leak site.