payload

Ransomware
Sourceransomware.live

About the group

Payload is a ransomware group that emerged in early 2026, using Babuk-derived source code targeting both Windows and ESXi systems with cross-platform double-extortion attacks against healthcare, energy, real estate, and agriculture sectors, claiming 12 victims across seven countries within hours of launching its leak site.

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

Impact and victims

The group payload has 1 known ransomware victims. See the most affected sectors and countries and recent victims.

1known victims
1in Brazil
1sectors hit
Most attacked sectors
Education1
Most affected countries
🇧🇷 Brasil1
Recent victims
Editora Irmãos VitaleEducation · BR · 2026-06-20

payload uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →