Skip to main content
Mallory
Back to malware
MalwareRansomwareUsed by 2 actorsExploits 1 CVE

PayoutsKing

PayoutsKing is a double-extortion ransomware operation linked in the provided reporting to the GOLD ENCOUNTER threat group. The malware operation steals victim data and encrypts files before demanding payment, and the reporting states it is not operated as a ransomware-as-a-service model and does not rely on affiliates. Sophos-linked activity ties PayoutsKing to the STAC4713 campaign, first observed in November 2025, in which attackers abused hidden QEMU virtual machines to evade host-based security controls, maintain covert access, harvest credentials, exfiltrate data, and ultimately deploy ransomware. The campaign used a scheduled task named TPMProfiler to launch qemu-system-x86_64.exe as SYSTEM, booting disguised virtual disk images such as vault.db and later bisrv.dll, with port forwarding from 32567 and 22022 to SSH and reverse SSH tunnels established via AdaptixC2 or OpenSSH. Reporting states the hidden VM used Alpine Linux 3.22.0 and contained tooling including Linker2, AdaptixC2, wg-obfuscator, BusyBox, Chisel, and Rclone. Initial access associated with PayoutsKing activity included exposed Cisco or SonicWall SSL VPN devices, exposed VPN systems lacking MFA, exploitation of SolarWinds Web Help Desk vulnerability CVE-2025-26399, and email-bombing followed by Microsoft Teams vishing. Post-compromise behavior associated with the operators included use of QuickAssist and SuperOps for remote access, Havoc C2 via DLL sideloading, SSH backdoors via AdaptixC2 or OpenSSH, credential harvesting including copying NTDS.dit, SAM, and SYSTEM hives over SMB, attempted AV/EDR disabling via BYOVD, and data exfiltration using WinSCP and Rclone to remote SFTP infrastructure. The content further states that PayoutsKing focuses on hypervisor environments and has developed encryptors for VMware and ESXi systems.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

1 CVES
CVE-2025-26399Unauthenticated AjaxProxy deserialization RCE in SolarWinds Web Help DeskExploited in the wild

Older incidents leveraged exposed SonicWall VPNs that did not have multi-factor authentication (MFA) enabled, while a January 2026 incident exploited a SolarWinds Web Help Desk vulnerability (CVE-2025-26399). In February, Microsoft and Huntress reported similar observations of this vulnerability leading to QEMU deployment.

via security affairssecurityaffairs.com
THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
GOLD ENCOUNTER

GOLD ENCOUNTER is a cybercriminal threat group that operators the PayoutsKing double extortion operation, stealing data and encrypting files before demanding a ransom payment from victims.

via sophos othersophos.com
STAC4713

AdaptixC2 is an open-source red-teaming framework that we’ve seen used in ransomware attacks, specifically as part of a threat activity cluster we track as STAC4713, involving PayoutsKing ransomware.

via sophos blogsophos.com
MITRE ATT&CK

Techniques & procedures

3 distinct techniques documented for this family, organized by ATT&CK tactic.

Execution

1 technique
T1610Deploy ContainerEvidence1
TacticExecution

The use of hidden virtual machines (VMs) enables long-term access, credential harvesting, data exfiltration, and PayoutsKing ransomware deployment

Stealth

1 technique
T1497Virtualization/Sandbox EvasionEvidence2

Threat actors are now weaponizing QEMU, a legitimate open-source machine emulator and virtualizer, as a covert backdoor... malicious activity running inside a virtual machine (VM) is essentially invisible to most endpoint protection tools.

Discovery

1 technique
T1497Virtualization/Sandbox EvasionEvidence2

Threat actors are now weaponizing QEMU, a legitimate open-source machine emulator and virtualizer, as a covert backdoor... malicious activity running inside a virtual machine (VM) is essentially invisible to most endpoint protection tools.

Impact

1 technique
T1486Data Encrypted for ImpactEvidence1
TacticImpact

Threat actors are now weaponizing QEMU... to steal credentials and deliver ransomware... The STAC4713 campaign... is directly linked to the PayoutsKing ransomware operation...

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities1

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping3

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.