Ransomware group profile · #137 by claimed victims
Payloadbin ransomware
PayloadBIN is a ransomware strain deployed in 2021 by Evil Corp as a rebranding of their WastedLocker/Hades/Phoenix lineage, specifically designed to evade US Treasury OFAC sanctions by impersonating the unrelated Babuk gang's rebrand rather than operating as an independent group.
Victimology
Who Payloadbin claims to have breached, from 29 leak-site posts recorded by VULONE.
Claims per month last 12 months
Top sectors
Top countries
Latest claimed victims 12 most recent
| Victim | Sector | Country | Claimed |
|---|---|---|---|
| aquila.ch aquila.ch | Technology | CH | 6 Jan 2022 |
| www.paw.eu paw.eu | Other | — | 1 Jan 2022 |
| Serenity Homes SWFL | Retail & E-Commerce | — | 1 Jan 2022 |
| www.hillsdalefurniture.com hillsdalefurniture.com | Retail & E-Commerce | — | 23 Dec 2021 |
| dawsoncountyne.org dawsoncountyne.org | Government & Defense | — | 19 Oct 2021 |
| www.lockslaw.com lockslaw.com | Professional Services | — | 16 Oct 2021 |
| calautomotive.com calautomotive.com | Retail & E-Commerce | — | 30 Sep 2021 |
| calsoft | Technology | — | 30 Sep 2021 |
| calsoft.com calsoft.com | Technology | — | 30 Sep 2021 |
| www.myyp.com myyp.com | Not Found | — | 25 Sep 2021 |
| Reconservices.com reconservices.com | Professional Services | — | 9 Sep 2021 |
| Capstoneins.com capstoneins.com | Financial Services | — | 9 Sep 2021 |
All 29 Payloadbin victims, searchable
Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.
Tactics, techniques and procedures
ATT&CK technique mapping for Payloadbin is in progress. Victimology, infrastructure status and leak-site tracking are live above.
Indicators, detections and the full playbook
Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.
Frequently asked
Is Payloadbin ransomware still active?
How many victims has Payloadbin claimed?
Which industries does Payloadbin target?
Which countries are most affected by Payloadbin?
Where does VULONE get Payloadbin victim data?
Other ransomware groups
Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].