Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors payoutsking

Also known as: Payouts King

Description

PayoutsKing is an active ransomware group observed through at least 2026 that has claimed attacks against a wide range of industries internationally — including Del Monte Foods and V. FRAAS — across the US, UK, Germany, and Ireland using standard double-extortion tactics. Known victims: 99 1 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 2 weeks ago

Executive Summary

PayoutsKing is an active ransomware group that has claimed attacks against a wide range of industries internationally, using standard double-extortion tactics to achieve financial gain. Since its first appearance in April 2025, the group has targeted multiple countries, including the US, UK, Germany, and Ireland. With 99 known victims, PayoutsKing poses a significant threat to organizations globally.

Goals & Targeting

PayoutsKing's strategic objectives appear to be focused on achieving financial gain through ransomware attacks, with a targeting profile that suggests a willingness to attack a wide range of industries and organizations. The group's attacks on Del Monte Foods and V. FRAAS demonstrate its ability to target high-profile victims, while its global reach and adaptability suggest that it may continue to expand its targeting profile in the future. Typical victims of PayoutsKing include organizations with valuable data and limited defensive capabilities, making it essential for companies to prioritize robust security measures and incident response planning.

Enhanced Description

The lack of specific targeting information and the group's broad attack surface suggest that PayoutsKing may be a relatively new or evolving threat actor. However, its ability to claim 99 known victims and operate undetected for an extended period highlights the need for organizations to remain vigilant and proactive in their defenses against ransomware threats. As the group continues to evolve, it is essential to monitor its activities and adapt defensive strategies to stay ahead of emerging threats.

Key Capabilities

  • Ransomware deployment
  • Double-extortion tactics
  • Data encryption
  • Global targeting
  • Adaptability and opportunism

MITRE ATT&CK Tactics

Data Encroachment
Exfiltration
Impact

ATT&CK Techniques

T1059.003
T1055
T1566.001

Software / Tooling

Custom ransomware
Encryption tools
Data exfiltration software

Campaigns & Victims

PayoutsKing's campaign patterns suggest a focus on rapid and efficient attacks, with a high volume of victims reported in a relatively short period. The group's operational tempo is likely driven by its financial motivations, with a focus on maximizing ransom payments and minimizing detection. Notable past operations include the attacks on Del Monte Foods and V. FRAAS, which demonstrate the group's ability to target high-profile victims and adapt its tactics to achieve its objectives.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 over DNS using fast-flux
  • Staging infrastructure on bulletproof hosting

Recommended Actions

  • Implement robust backup and disaster recovery procedures
  • Conduct regular security audits and penetration testing
  • Develop an incident response plan for ransomware attacks
  • Provide employee training on phishing and social engineering attacks

Suggested Tags

Ransomware
Criminal
Double-extortion
Financial gain

Confidence Assessment

The confidence level in the available data is medium, with some information gaps existing regarding the group's specific targeting profile and technical capabilities. While PayoutsKing's attacks on Del Monte Foods and V. FRAAS provide valuable insight into its tactics, further research is needed to fully understand the group's motivations and operational tempo. Additional intelligence gathering and analysis are required to fill these gaps and provide a more comprehensive understanding of the threat posed by PayoutsKing.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

47

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Critical Infrastructure

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Apr 17, 2025
Last Seen
Aug 3, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.