Ransomware Group intelligence
Payload
ActiveTrack Payload with 39 published victims and 2 known leak locations in a single intelligence view.
Overview
Payload is tracked by Breach House as a ransomware group with 39 published victims.
United States is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Unknown | payloadrz5yw227brtbvdqpnlhq3rdcdekdnn3rgucbcdeawq2v6vuyd.onion |
| Leak location 2 | Onion service | Unknown | payloadynyvabjacbun4uwhmxc7yvdzorycslzmnleguxjn7glahsvqd.onion |
Top Activity Sectors
No sector intelligence available.
Ransom Notes (0)
▼No ransom notes available for this group.
Tools Used
▼No tools used available.
YARA Rules (0)
▼No YARA rules available.
Indicators of Compromise (0)
▼No IoCs available for this group.
Negotiation Chats (0)
▼No negotiation chats available.
Research Sources
No external research sources linked yet.
Victims (39)
Search, filter and paginate the victim timeline for Payload.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Peroni Sosa Tellechea Burt & Narvaja id28414 View details | Uruguay | Finance / Legal / Insurance | ||
|
PSTBN Peroni Sosa Tellechea Burt & Narvaja is one of the largest and most prestigious law firms in Paraguay, founded in 1968. The firm is committed to meeting the diverse legal needs of its clients across various practice areas, including corporate law, tax law, agribusiness, and regulatory compliance. |
|||||
| Ransomware | meditron.com.ve id28413 View details | Venezuela, Bolivarian Republic of | Healthcare / Medicine | ||
|
Meditron C.A. is a Venezuelan company founded in 1972, specializing in the marketing and after-sales service of medical equipment. They also design, construct, and equip healthcare infrastructures, providing comprehensive solutions in the health sector. Their offerings include a wide range of medical devices and technical support services, catering to various healthcare needs. Meditron represents globally recognized brands and is committed to supporting medical innovation and excellence in Venezuela. |
|||||
| Ransomware | b3-bruck.at id28412 View details | Austria | Construction / Real Estate | ||
|
B3-Bruck is an Austrian company specializing in IT services and network solutions. They provide hosting, virtual servers, and colocation, along with network management and security services. The company also offers IT consulting and infrastructure support for corporate clients. |
|||||
| Ransomware | caravaningcity.com id28411 View details | Germany | Retail / E-commerce | ||
|
Caravaning City is a travel and lifestyle platform focused on caravanning and RV adventures. They provide information, products, and services for camping enthusiasts, including motorhomes, caravans, and camping accessories. The site also offers trip planning resources and guides for exploring caravan-friendly destinations. |
|||||
| Ransomware | JOH Investments Limited id28340 View details | Finance / Legal / Insurance | |||
|
JOH Investments Limited is an officially registered financial entity based in Kingston, Jamaica, holding an active Legal Entity Identifier (LEI) for international operations. The company specializes in investment activities and asset management, maintaining integration with global banking systems for financial transactions. |
|||||
| Ransomware | Better House id28331 View details | Construction / Real Estate | |||
|
Better House Development specializes in real estate projects, offering a wide range of properties including residential apartments, villas, and various types of houses such as Twin Houses and Town Houses. The company has successfully implemented over 150 projects, focusing on providing high-quality service and maximizing return on investment for its clients. Their developments are located in prominent areas such as New Capital, Sky Capital, and Galala City. |
|||||
| Ransomware | Al Sulaiti Law Firm id28330 View details | Qatar | Finance / Legal / Insurance | ||
|
Al Sulaiti Law Firm is one of the largest law firms in Qatar, established in 2002, offering a wide range of legal services including arbitration, banking, corporate, employment, energy, and intellectual property. The firm emphasizes teamwork and collaboration, aiming to build strong relationships with clients to exceed their expectations. With a diverse and innovative team, they provide high-quality professional services tailored to meet the unique needs of their clients. Their commitment to integrity and client satisfaction has earned them recognition and respect in the legal community. |
|||||
| Ransomware | Franziskusschule Wilhelmshaven id28255 View details | Germany | Education | ||
|
Franziskusschule Wilhelmshaven is a school located in Wilhelmshaven, a city in northern Germany on the North Sea coast. The name “Franziskusschule” indicates that it is a Franciscan or Catholic school, often inspired by the values of Saint Francis of Assisi, emphasizing community, social responsibility, and moral education alongside academic learning. |
|||||
| Ransomware | Marino Food Products Pvt id28254 View details | Sri Lanka | Agriculture / Food | ||
|
Marino Food Products Pvt Ltd, based in Hyderabad, India, specializes in a wide range of healthy and delicious bakery items including biscuits, cookies, cakes, and breads. The company is dedicated to providing high-quality food products that combine wellness with taste, making them an ideal choice for health-conscious consumers. Their offerings are available for online ordering and in various retail stores, ensuring accessibility for their clients. Marino aims to be the go-to destination for snacking bliss, with a commitment to crafting irresistible snacks that satisfy cravings while promoting a healthy lifestyle. |
|||||
| Ransomware | Sunlight Express Airways id28253 View details | Transportation / Travel / Logistics | |||
|
Sunlight Air offers affordable flights to popular Philippine island destinations such as Cebu, Coron, Boracay, Siquijor, and Siargao. The airline provides various services including private charters, vacation packages, and a loyalty program called Sunlight Miles. Targeting both leisure and business travelers, Sunlight Air aims to enhance the travel experience with exclusive passenger perks and flexible booking options. With a commitment to expanding flight frequencies and routes, the company continues to facilitate convenient travel across the Philippines. |
|||||
| Ransomware | orientalweavers.com id28252 View details | Egypt | Manufacturing / Engineering | ||
|
Established in 1979, Oriental Weavers is a manufacturer of textiles used to construct rugs, carpet, upholstery, and more. This company is headquartered in Cairo, Egypt |
|||||
| Ransomware | TFE Group id28251 View details | Australia | Transportation / Travel / Logistics | ||
|
TFE Group is a company that operates in the Architecture, Engineering & Design industry. |
|||||
| Ransomware | El Wastani Petroleum Company (WASCO) id27962 View details | Libya | Energy | ||
|
El Wastani Petroleum Company (WASCO) is an Egyptian oil and gas company focused on the exploration, production, and processing of natural gas and condensate. It operates fields and infrastructure, including processing facilities and compression stations, mainly in the Nile Delta and North Sinai regions. The company serves as a regional operator, supporting the development of Egypt’s gas industry. |
|||||
| Ransomware | United Finance Egypt id27844 View details | Egypt | Finance / Legal / Insurance | ||
|
United Finance Egypt is an Egyptian non-bank financial institution (NBFI) that provides financing services for businesses and real estate. It operates in several areas: financial and operating leases, factoring, and mortgage lending. The data breach involves the company’s entire infrastructure. The majority of the leaked data consists of the company’s customer information. |
|||||
| Ransomware | Tscherne Consulting Steuerberatung GmbH id27843 View details | Austria | Finance / Legal / Insurance | ||
|
Tscherne Consulting Steuerberatung GmbH is an Austrian tax consulting firm based in Graz. The company specializes in services for small and medium-sized businesses, including bookkeeping, tax planning, payroll processing, and business consulting. |
|||||
| Ransomware | SAYEGH id27800 View details | Manufacturing / Engineering | |||
|
Sayegh 1944 presents itself as an educational company, yet its activities appear broad and somewhat lacking in transparency. Under the umbrella of developing learning materials and services for schools, it spans multiple areas where a clear core expertise is hard to identify. Overall, it gives the impression of an organization trying to cover many segments of education without demonstrating a strong, well-defined specialization or standout results. |
|||||
| Ransomware | NKAR Travels & Tours id27725 View details | Sri Lanka | Hospitality / Food & Beverage / Tourism | ||
|
NKAR Travel House is a premier travel agency in Sri Lanka, offering a diverse range of carefully curated tours and travel packages tailored to various interests. Their services include classical, cultural, wildlife, wedding, and experiential tours, as well as luxury options and tailor-made experiences. The agency aims to provide guests with unforgettable journeys through Sri Lanka's rich heritage, stunning landscapes, and vibrant culture. |
|||||
| Ransomware | Q2 Artificial Lift Services id27643 View details | Canada | Energy | ||
|
Q2 Artificial Lift Services is a leading company specializing in the sales, service, engineering, and manufacturing of down hole rod pumps. With a state-of-the-art facility in Red Deer, Alberta, and over 40 service locations across Canada and the USA, they provide innovative solutions and technical support. Their product range includes various types of rod pumps, production tools, and specialty accessories. Q2 aims to maximize productivity and enhance the operational lifespan of their clients' pumping systems. |
|||||
| Ransomware | Don-Nan id27642 View details | United States | Manufacturing / Engineering | ||
|
Q2 Artificial Lift Services specializes in the sales, service, engineering, and manufacturing of down hole rod pumps, positioning itself as a leader in artificial lift technology. The company operates from a state-of-the-art 118,000 sq. ft. facility and boasts over 40 service and repair locations across Canada and the USA. Q2 offers a comprehensive range of products, including API pumps, specialty tubing, and production tools, combined with supportive engineering and technical services. Their commitment to quality and innovation enables them to provide tailored solutions that maximize productivity for their clients in the oilfield sector. |
|||||
| Ransomware | A A Al Moosa Enterprises (ARENCO Group) id27637 View details | United Arab Emirates | Construction / Real Estate | ||
|
A.A. Al Moosa Enterprises, also known as ARENCO Group, is a diversified conglomerate based in Dubai, with interests spanning architectural and engineering consulting, real estate, hospitality, car rentals, manufacturing, and interior design. Established in 1971, the group has grown into one of the top family-owned business groups in Dubai, focusing on quality, service, and innovation. |
|||||
| Ransomware | carlysle.net id27607 View details | United States | Services | ||
|
Carlysle.net belongs to Carlysle Engineering, Inc., an engineering firm based in Boston. The company specializes in designing, installing, and maintaining fire protection systems such as sprinklers. They also provide building inspections and consulting services to ensure compliance with safety and insurance requirements. |
|||||
| Ransomware | Vancompare Insurance id27562 View details | United Kingdom | Finance / Legal / Insurance | ||
|
Vancompare.co.uk is a UK-based online comparison service that helps users find the best insurance deals for cars, homes, businesses, and other types of coverage. The site allows users to quickly compare prices and terms from multiple insurance providers to choose the most suitable and cost-effective policy. |
|||||
| Ransomware | iGLS id27538 View details | Spain | Healthcare / Medicine | ||
|
IGLS Laboratorio specializes in genetic and reproductive immunology, providing advanced diagnostic services tailored for assisted reproduction centers, specialists, hospitals, and healthcare institutions worldwide. The company is committed to innovation, utilizing cutting-edge technology and scientific advancements to deliver precise solutions for fertility issues. Their extensive range of services includes preconception, preimplantation, and prenatal testing, aimed at both medical professionals and patients facing infertility challenges. |
|||||
| Ransomware | HOPPECKE Singapore id27504 View details | Singapore | — | ||
|
HOPPECKE Asia Pacific Pte Ltd is the regional headquarters of the HOPPECKE Batteries Group in Singapore. It manages sales, service, and distribution for the Asia-Pacific region, providing industrial energy storage solutions. The company supports sectors including renewable energy, rail, telecommunications, and logistics. |
|||||
| Ransomware | TS Lines Philippines id27484 View details | Philippines | — | ||
|
Trusted shipping and logistics partner in the Philippines offering container transport and vessel services. |
|||||
| Ransomware | Lucky Innovative Manufacturing Corporation id27454 View details | Philippines | — | ||
|
Lucky Innovative Manufacturing Corporation is a company based in Lipa City, Batangas, Philippines, specializing in the import and export of textiles and apparel products, including fabrics, hats, gloves, and other items from the garment industry. The company is registered as an international trading participant and is listed in global trade databases as a supplier and importer across various countries. Its operations focus on manufacturing and distributing goods to international markets, leveraging its strategic location in the Philippines. |
|||||
| Ransomware | Notaría 89 id27453 View details | Mexico | — | ||
|
Notaría 89 – Edomex, located in the State of Mexico, offers specialized legal services for various real estate transactions and contracts. Under the leadership of Licenciado Luis Octavio Hermoso y Colín, the notary public provides services such as the granting of powers, purchase contracts, real estate mortgages, and the constitution of societies. The notary public also handles testaments and other notarial services, ensuring all legal requirements are met for property transfers and other legal matters. |
|||||
| Ransomware | Royal Bahrain Hospital id27346 View details | Bahrain | — | ||
|
Established in 2011, Royal Bahrain Hospital (RBH) is a leading healthcare facility in Bahrain, offering a wide range of medical specialties and services. The hospital is equipped with 70 beds and provides both inpatient and outpatient care, including operating rooms, maternity services, and various diagnostic facilities. RBH is committed to delivering quality and affordable healthcare to its patients, with a focus on clinical excellence and patient satisfaction. The hospital serves a diverse clientele, including residents of Bahrain and neighboring countries such as Oman, Qatar, Saudi Arabia, and the UAE. |
|||||
| Ransomware | J.T. Pack of Foods id27335 View details | — | |||
|
J.T. Pack of Foods Co., Ltd. is a Thai company that specializes in food packaging solutions for businesses such as restaurants, hotels, and food manufacturers. Founded in 1989, it offers a wide range of packaging products, including plastic, paper, and eco-friendly materials, as well as custom branding services. The company operates as both a manufacturer and distributor, serving thousands of clients across Thailand. |
|||||
| Ransomware | Grid Fine Finishes id27334 View details | United Kingdom | — | ||
|
Grid Fine Finishes (GFF) is an Egyptian company based in Cairo that specializes in interior fit-out and fine finishing services. The company delivers turnkey projects, including interior construction, electro-mechanical works, lighting, and custom furniture solutions. Founded in 2015, GFF focuses on commercial, hospitality, and residential spaces. |
|||||
| Ransomware | Alcoholes Finos Dominicanos id27333 View details | Dominican Republic | — | ||
|
Alcoholes Finos Dominicanos, S.A. (AFD) is a Dominican company that produces food-grade alcohol and rum-related spirits using sugarcane juice as its main raw material. The company focuses on alcohol production for human consumption and uses industrial distillation processes with quality and sustainability programs. |
|||||
| Ransomware | In.Sa.Cor id27332 View details | United States | — | ||
|
InSaCor specializes in a wide range of gas-related products and sanitary solutions, including gas regulators, fittings, and various types of plumbing fixtures. Their offerings include high-quality materials for both residential and commercial applications, catering to clients in the construction and maintenance sectors. |
|||||
| Ransomware | Easy Servizi id27331 View details | Italy | — | ||
|
Easy Servizi is an Italian company that provides technical and operational services for utility network operators (gas, electricity, and water), including meter installation and replacement, network support, and customer data management. It operates as a contractor for energy and water companies rather than as a direct service provider to consumers. |
|||||
| Ransomware | Thai Solar Energy Public id27330 View details | Thailand | — | ||
|
Thai Solar Energy Public Company Limited (TSE) was established in 2008 based in Bangkok, Thailand. TSE is the first in Southeast Asia to have effectively applied an advanced technology to utilize the sun's radiation and converting it into green energy. TSE is in collaboration with several World renowned energy institutes and specialized energy companies to continuously evaluate our performance. |
|||||
| Ransomware | United Limsun International Trading id27329 View details | Philippines | — | ||
|
United Limsun Corporation is a rapidly growing retail and distribution company that selects multifunctional brands of everyday goods for urban travellers. The company specialises in sourcing, supplying, distributing and marketing high-quality goods. |
|||||
| Ransomware | Tyler Media id27328 View details | United States | — | ||
|
Tyler Media is a comprehensive media company in Oklahoma, offering a variety of services that include radio, television, and outdoor advertising. With several radio stations and partnerships with prominent television networks, they cater to a diverse audience, showcasing both English and Spanish content. Their key clients range from local businesses to larger organizations seeking effective marketing solutions and brand awareness. |
|||||
| Ransomware | Río Grande (Puerto Rico) id27327 View details | Puerto Rico | — | ||
|
Río Grande is a municipality located in Puerto Rico, a U.S. territory in the Caribbean. It has its own local government that manages public services, administration, and community programs for residents. |
|||||
| Ransomware | sodic.com id26619 View details | Egypt | Construction / Real Estate | ||
|
SODIC is a leading real estate development company in the region, with a distinguished track record of over 28 years of operations in West Cairo, East Cairo, and the North Coast. SODIC brings to the market award-winning developments that cater to the country’s ever-growing need for high-quality residential, commercial, & retail property as well as sustainable, large-scale, mixed-use developments and vibrant communities that are home to over 30,000 people today. SODIC is listed on the Egypt’s Stock Exchange since 1996 under OCDI.CA. |
|||||
| Ransomware | Almacenes Distribuidores de la Frontera id26618 View details | Mexico | Energy | ||
|
Almacenes Distribuidores de la Frontera ha forjado una trayectoria sólida en el Estado de Chihuahua. Desde sus inicios, la empresa ha evolucionado para convertirse en un referente en la industria de tiendas de conveniencia, gasolineras y embotelladoras de agua. Dos nombres que resuenan fuertemente en el mercado son Superette y Del Rio. Estas tiendas de conveniencia se han convertido en destinos confiables para los consumidores que buscan conveniencia, variedad y un servicio excepcional. |
|||||