Payouts King Rises as New Ransomware Threat Linked to Former BlackBasta Affiliates
ID: db10a45c-0b79-5da7-bcbe-3eaefd16312f
STIX ID: report--db10a45c-0b79-5da7-bcbe-3eaefd16312f
Feed Name: cybersecurityNews.com
Payouts King is an active and technically sophisticated ransomware group that emerged after the collapse of BlackBasta; it performs targeted attacks combining spam bombing, Microsoft Teams social engineering, abuse of Quick Assist for remote access, large-scale data theft, selective file encryption using 4,096-bit RSA and AES-256-CTR, and publishes stolen data on a Tor-based leak site. The malware includes strong anti-analysis features (stack-based string encryption, hashed API resolution, custom CRC, anti-sandbox checks) and uses direct syscalls to disable 131 AV/EDR products, then deletes shadow copies and logs to impede recovery and forensics.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
