payload
Payload is a ransomware group that emerged in early 2026, using Babuk-derived source code targeting both Windows and ESXi systems with cross-platform double-extortion attacks against healthcare, energy, real estate, and agriculture sectors, claiming 12 victims across seven countries within hours of launching its leak site.
observed victims (by country)
SwitzerlandGermanyJordanSouth Africa
observed sectors
ManufacturingTechnologyProfessional ServicesFinancial Services
12 victims · last active 20 Aug 2026
recent activity · our intel
source: ransomware.live1 refs →