logo

Payouts King Takes Aim at the Ransomware Throne

ID: 1486e15a-63f4-5b84-948a-583d5b15f9df

STIX ID: report--1486e15a-63f4-5b84-948a-583d5b15f9df

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2026-04-16

Date Updated: 2026-05-01

...
...

This technical analysis of the Payouts King ransomware describes how actors use spam/phishing/vishing to obtain remote access, details obfuscation (custom CRC, per-value FNV1 hashing, stack-based QWORD strings), persistence via scheduled tasks, privilege elevation, low-level syscall-based process termination to evade EDR, and file encryption using per-file AES-CTR with RSA-wrapped parameters, while excluding common system files and optionally publishing stolen data on a Tor-accessible leak site.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.