Payload Ransomware — Victims, Campaigns & Activity

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
March 16, 2026
Last Seen
May 26, 2026

Payload is a ransomware_group tracked by ThreatCluster, appearing in 3 threat clusters built from 4 intelligence report mentions.

Payload is a ransomware_group tracked across 3 threat clusters and 4 intelligence report mentions on ThreatCluster. First observed March 16, 2026; most recent activity May 26, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • Payload Ransomware Uses ChaCha20 and Curve25519 ECDH to Encrypt Windows Files — Cybersecuritynews · May 26, 2026
  • New ‘Payload’ Ransomware Uses Babuk — Cybersecuritynews · March 17, 2026
  • Payload ransomware hits Windows and ESXi with Babuk — Gbhackers · March 17, 2026
  • Royal Bahrain Hospital breach, Canada's Loblaw breached, New York water laws — Linkedin · March 16, 2026

Frequently asked questions

What is Payload?

Payload is a ransomware_group tracked by ThreatCluster, appearing in 3 threat clusters built from 4 intelligence report mentions.

Is Payload still active?

The most recent intelligence report mentioning Payload on ThreatCluster is dated May 26, 2026. Activity was first observed March 16, 2026, giving a tracked span from then to May 26, 2026.

What is Payload associated with?

Across ThreatCluster reporting, Payload most frequently co-occurs with ShinyHunters, Data Breach, Ransomware, Loblaw, National Centre For Nuclear Research, among 12 tracked related entities.

What are the latest developments involving Payload?

The most significant recent cluster is “Payload Ransomware Targets Global Organizations with ChaCha20 Encryption” (2 articles · Updated May 26, 2026). Payload appears across 3 threat clusters in total, listed above with sources.

How much reporting does ThreatCluster have on Payload?

Payload appears in 4 intelligence report mentions across 3 deduplicated threat clusters, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown