Payouts King Takes Aim at the Ransomware Throne
ID: 1486e15a-63f4-5b84-948a-583d5b15f9df
STIX ID: report--1486e15a-63f4-5b84-948a-583d5b15f9df
Feed Name: Zscaler Security Research Blog
This technical analysis of the Payouts King ransomware describes how actors use spam/phishing/vishing to obtain remote access, details obfuscation (custom CRC, per-value FNV1 hashing, stack-based QWORD strings), persistence via scheduled tasks, privilege elevation, low-level syscall-based process termination to evade EDR, and file encryption using per-file AES-CTR with RSA-wrapped parameters, while excluding common system files and optionally publishing stolen data on a Tor-accessible leak site.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
