Ransomware Intelligence

payoutsking

Ransomware group profile

105Victims
UnknownSource country
75Impact score
Also Known As
PK Crew
Payout$King
Payouts_KING
payoutsking
PayoutsMafia

Description

PayoutsKING is a newly-identified ransomware group that surfaced in July 2025, primarily targeting hospitals, manufacturers, and educational institutions. The group's operations appear to follow a ransomware-as-a-service model, rapidly listing victims on data leak sites and employing aggressive financial extortion tactics.

Key insights

  • Targets diverse sectors, including healthcare, manufacturing, and education.
  • Utilizes remote desktop protocol (RDP) access, phishing templates, and cracked panel kits for initial access.
  • Employs various malware families like Azorult and RedLine for data theft and credential harvesting.
  • Adopts a victim-centric approach, quickly disclosing compromised data on leak sites.
  • Active in both North America and Europe, with a broad geographic reach.
  • Indicates a strong financial motivation, evident in aggressive ransom demands.

Threat Level & Status Breakdown

For payoutsking · Based on incidents in selected period

2.2threat level
Aggressiveness6/ 10
Lethality0/ 10
Criticality0.3/ 10

Status Breakdown

Claimed40.0%42
First seenJul 2025
Last seenJun 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedJun 18, 2026

Recent activity

Monthly attack count for payoutsking in the selected period

105Total attacks
43peak in Apr
9.5avg / month
↓ 7 vs first month
JulAugSepOctNovJanFebMarAprMayJun015304560

Intelligence

IOCs, YARA/Sigma rules, and related families for payoutsking

  1. 78d75669390e4177597faf9271ce3ad3a16a3652e145913dbfa9a5951972fcb0
  2. 6f55743091410dad6cdb0b7e474f03e7
  3. 8c8e75dc4b4e1f201b56133a00fa9d1d711ccb50
  4. 3a33b5bceb1eba4cc749534b03dd245f965d8f200aa02392baad78f5021a20ff
  5. b752ebfc1004f2c717609145e28243f3
  6. 94f73b5dc06ba6705fcef3e759413a747049c2949a0c2e44afc03b2f9989cf73
  7. 61c14c01460810f6f5f760daf8edbda82eea908b1a95052f8e0f9c4162c2900c
  8. 25e4d0eacff44f67a0a9d13970656cf76e5fd78c
  9. c3804d1329b55a37bfa2f835e1e9bbc7bdb2b260f8e3627c06e02c9f52685d44
  10. b186baf2653c6c874e7b946647b048cc
  11. 903edad58d54f056bd94c8165cc20e105b054fa8
  12. f7a11aeaa4f0c748961bbebb2f9e12b6
  13. 2a728d98ae8280efeaa674783181f3fa
  14. 6c09b0d102361888daa7fa4f191f603a19af47cb
View full IOC feed500 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for payoutsking

Other

T1486

T1486

T1490

T1490

T1078

T1078

T1021

T1021

T1562

T1562

T1059

T1059

T1547

T1547

T1021.001

T1021.001

T1005

T1005

T1041

T1041

T1080

T1080

Victims(105)

CompanyDomainCountryIndustryStatusDiscovered
W****e
Unknown
4 days ago
T****C
Unknown
22 days ago
Caunton Engineeringcaunton.co.ukGB United KingdomManufacturing
Claimed
about 2 months ago
V. FRAASvfraas.comDE GermanyManufacturing
Claimed
about 2 months ago
Bespoke Home Interior Design Groupbhid.co.ukGB United KingdomManufacturing
Claimed
about 2 months ago
Vortex Companiesvortexcompanies.comUS United StatesOther
Claimed
about 2 months ago
Telia Norge AStelia.noNO NorwayTechnology
Claimed
about 2 months ago
Prater Engineering Associatespraterengineering.comUS United StatesProfessional Services
Claimed
about 2 months ago
ESENTIA Energy Systemsesentiaenergy.comMX MexicoEnergy & Utilities
Claimed
about 2 months ago
Del Monte Foodsdelmontefoods.comUS United StatesManufacturing
Claimed
about 2 months ago
I****Gim****.comUS United StatesTransportation
Unknown
about 2 months ago
O****Co****.comUS United StatesTechnology
Unknown
about 2 months ago
UFP Technologiesufpt.comUS United StatesManufacturing
Claimed
about 2 months ago
G****sg****.comUS United StatesManufacturing
Unknown
about 2 months ago
E****be****.comUS United StatesTechnology
Unknown
about 2 months ago
Aero-Coatingaero-coating.deDE GermanyManufacturing
Claimed
about 2 months ago
Peachtree Grouppeachtreegroup.comUS United StatesHospitality
Claimed
about 2 months ago
Ash & Lacy Holdingsashandlacy.comGB United KingdomManufacturing
Claimed
about 2 months ago
Maderas del Alto Urgelmausa.esES SpainManufacturing
Claimed
about 2 months ago
Eyemart Expresseyemartexpress.comUS United StatesRetail & E-Commerce
Claimed
about 2 months ago

Page 1 of 6