Payload ransomware hits Windows and ESXi with Babuk-style encryption
ID: febc3fee-395a-5c00-b364-4dc80150005c
STIX ID: report--febc3fee-395a-5c00-b364-4dc80150005c
Feed Name: GBHackers
Threat Score
Payload is an emerging, high-impact ransomware operation active since at least February 2026 that combines Babuk-style cryptography (Curve25519 ECDH, ChaCha20) with aggressive anti-forensics, EDR/backup disruption, and a double-extortion leak site; it targets both Windows and VMware ESXi (VM disk encryption) and has claimed multiple mid-to-large victims across sectors including healthcare, real estate, energy, telecom, and agriculture.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
