DisclosureLens
← All groups

payloadbin

Active since 2021-09-09
29 claimed victims

Unverified threat-actor claim — not a regulatory filing

Attribution, victim identity, and counts shown here derive from payloadbin's public extortion-blog claims, aggregated by ransomware.live. They have not been validated by the victim or any regulator. Treat them as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.

According to ransomware.live, the group claims:

PayloadBIN is a ransomware strain deployed in 2021 by Evil Corp as a rebranding of their WastedLocker/Hades/Phoenix lineage, specifically designed to evade US Treasury OFAC sanctions by impersonating the unrelated Babuk gang's rebrand rather than operating as an independent group.

Source: Ransomware.live

Payloadbin ransomware group · DisclosureLens