Payloadbin

Inactive
PayloadBIN is a ransomware strain deployed in 2021 by Evil Corp as a rebranding of their WastedLocker/Hades/Phoenix lineage, specifically designed to evade US Treasury OFAC sanctions by impersonating the unrelated Babuk gang's rebrand rather than operating as an independent group.
29 Victims
Sep 9, 2021 First Discovered
Jan 6, 2022 Last Discovered
1714 Days Inactive
0% Infostealer
0/1 Sites Online
Known Locations (1)
Payload.bin
vbmisqjshn4yblehk2vbnil53tlqklxsdaztgphcilto3vdj4geao5qd.onion
Victims (29)

Detailed victim list temporarily unavailable

This group has 29 victims. The victim list API is currently responding slowly for this dataset. Country, sector, and infostealer breakdowns are not available at this time. Basic stats (victim count, first/last seen) are shown above from a faster data source.