Payload is a ransomware_group tracked by ThreatCluster, appearing in 3 threat clusters built from 4 intelligence report mentions.
Payload is a ransomware_group tracked across 3 threat clusters and 4 intelligence report mentions on ThreatCluster. First observed March 16, 2026; most recent activity May 26, 2026.
Payload ransomware, first identified in February 2026, has rapidly expanded its operations, targeting logistics, real estate, and manufacturing sectors worldwide. The malware employs ChaCha20 encryption and Curve25519…
A new ransomware strain named 'Payload' has emerged, posing a significant threat to organizations utilizing Windows and VMware ESXi systems. The group behind Payload has been active since at least February 17, 2026, and…
The Payload Ransomware group has claimed responsibility for breaching the Royal Bahrain Hospital (RBH), a prominent healthcare facility in Bahrain, and has stolen 110 GB of sensitive data. The group has added RBH to its…
Payload is a ransomware_group tracked by ThreatCluster, appearing in 3 threat clusters built from 4 intelligence report mentions.
The most recent intelligence report mentioning Payload on ThreatCluster is dated May 26, 2026. Activity was first observed March 16, 2026, giving a tracked span from then to May 26, 2026.
Across ThreatCluster reporting, Payload most frequently co-occurs with ShinyHunters, Data Breach, Ransomware, Loblaw, National Centre For Nuclear Research, among 12 tracked related entities.
The most significant recent cluster is “Payload Ransomware Targets Global Organizations with ChaCha20 Encryption” (2 articles · Updated May 26, 2026). Payload appears across 3 threat clusters in total, listed above with sources.
Payload appears in 4 intelligence report mentions across 3 deduplicated threat clusters, aggregated from 17,000+ monitored sources.