Ransomware needs a way in. Stolen credentials are the cheapest one.
PayoutsKING Ransomware Group
Ransomware group profile
Description
PayoutsKING is a newly-identified ransomware group that surfaced in July 2025, primarily targeting hospitals, manufacturers, and educational institutions. The group's operations appear to follow a ransomware-as-a-service model, rapidly listing victims on data leak sites and employing aggressive financial extortion tactics.
Key insights
- •Targets diverse sectors, including healthcare, manufacturing, and education.
- •Utilizes remote desktop protocol (RDP) access, phishing templates, and cracked panel kits for initial access.
- •Employs various malware families like Azorult and RedLine for data theft and credential harvesting.
- •Adopts a victim-centric approach, quickly disclosing compromised data on leak sites.
- •Active in both North America and Europe, with a broad geographic reach.
- •Indicates a strong financial motivation, evident in aggressive ransom demands.
Threat Level & Status Breakdown
For PayoutsKING · Based on incidents in selected period
Recent activity
Monthly attack count for PayoutsKING in the selected period
Intelligence
IOCs, YARA/Sigma rules, and related families for PayoutsKING
- 78d75669390e4177597faf9271ce3ad3a16a3652e145913dbfa9a5951972fcb0
- c3804d1329b55a37bfa2f835e1e9bbc7bdb2b260f8e3627c06e02c9f52685d44
- 7eec7d07587112777016e5742c0d002d7e64a3e1fe7bde82fed8f65e3663456a
- e1c371c7c39c16d208bcbaa5b5d0714df696e6ef68b95a880673a904527c8b96
- 94f73b5dc06ba6705fcef3e759413a747049c2949a0c2e44afc03b2f9989cf73
- e06520c65bf27d9110d68ecc0de0e0824c3a99be080ead1a5b5be8fd2a26d12d
- 3c7c91cd4dc336db8082e07ab7549556f05d80acbc778afc2dade67c02002f69
- 2a728d98ae8280efeaa674783181f3fa
- b186baf2653c6c874e7b946647b048cc
- a65f0144101d93656c5f9ad445b3993336e1f295a838351aeca6332c0949b463
- 903edad58d54f056bd94c8165cc20e105b054fa8
- eae09889399fe4fb8e78b114dba0527de913d12fb1802944a88ed136e3e90577
- f3194018d60645e43afabac33ceb4e852f95241b410cd726b1c40e3021589937
- c6b848c6a61685724fa9e2b3f6e3a118323ee0c165d1aa8c8a574205a4c4be59
- 7ae413b76424508055154ee262c7567705dc1ac00607f5ac2e43d032221b34b3
- 61c14c01460810f6f5f760daf8edbda82eea908b1a95052f8e0f9c4162c2900c
- 3a33b5bceb1eba4cc749534b03dd245f965d8f200aa02392baad78f5021a20ff
- 8c8e75dc4b4e1f201b56133a00fa9d1d711ccb50
- 6c09b0d102361888daa7fa4f191f603a19af47cb
- 66dc383e9e0852523fe50def0851b9268865f779
- 25e4d0eacff44f67a0a9d13970656cf76e5fd78c
- f7a11aeaa4f0c748961bbebb2f9e12b6
- b752ebfc1004f2c717609145e28243f3
- 6f55743091410dad6cdb0b7e474f03e7
TTPs & Attack Vectors
Tools, initial access, and MITRE ATT&CK techniques for PayoutsKING
T1486
T1486
T1490
T1490
T1078
T1078
T1021
T1021
T1562
T1562
T1059
T1059
T1547
T1547
T1021.001
T1021.001
T1005
T1005
T1041
T1041
T1080
T1080
Victims(54)
| Company | Country | Status | Discovered | |
|---|---|---|---|---|
| Proliance Surgeons | United States | Claimed | 16 days ago | |
| Turner | United States | Claimed | about 1 month ago | |
| H.W. Lochner | United States | Claimed | 21 days ago | |
| Casta Diva Group | Italy | Claimed | 2 months ago | |
| Welldyne | United States | Claimed | 3 months ago | |
| Caunton Engineering Ltd | United Kingdom | Claimed | 5 months ago | |
| V. FRAAS | Germany | Claimed | 5 months ago | |
| BHID Group | United Kingdom | Claimed | 5 months ago | |
| Vortex Companies | United States | Claimed | 5 months ago | |
| Telia | Norway | Claimed | 5 months ago | |
| Prater Engineering Associates, Inc. | United States | Claimed | 5 months ago | |
| ESENTIA Energy Systems | Mexico | Claimed | 5 months ago | |
| Del Monte Foods | United States | Claimed | 5 months ago | |
| UFP Technologies | United States | Claimed | 5 months ago | |
| AERO-COATING GmbH | Germany | Claimed | 5 months ago | |
| Peachtree Group | United States | Claimed | 5 months ago | |
| Ash & Lacy Holdings | United Kingdom | Claimed | 5 months ago | |
| MAUSA | Spain | Claimed | 5 months ago | |
| Eyemart Express | United States | Claimed | 5 months ago | |
| Sofinter | Italy | Claimed | 5 months ago |
Page 1 of 3
Affected countries(54)
Countries where this group has been reported to target or leak victims.