THREAT ACTOR
PAYLOADBIN_
DormantPAYLOADBIN is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem: file encryption combined with the threat of stolen-data publication on a public leak site. It continues to post fresh victim claims as part of an ongoing extortion campaign.
For Ransomnews editorial coverage of PAYLOADBIN, including incident write-ups, attribution notes and additional context, see the Threat Groups archive or run a site search.
Victims by year
- 2022 3
- 2021 27
Leak site mirrors
1 mirror tracked, 0 currently reachable. These are criminal-infrastructure URLs; links are deliberately not provided.
-
vbmisqjshn4yblehk2vbnil53tlqklxsdaztgphcilto3vdj4geao5qd.onionPayload.bin snapshot · 2022-08-27 14:02
Recent victims
The 50 most recent victims claimed by PAYLOADBIN. Total in the index: 30.
| Date listed | Victim | Description |
|---|---|---|
| 2022-01-06 | aquila.ch | |
| 2022-01-01 | www.paw.eu | |
| 2022-01-01 | Serenity Homes SWFL | |
| 2021-12-29 | iRely LLC's Grand Failure | |
| 2021-12-23 | www.hillsdalefurniture.com | |
| 2021-10-19 | dawsoncountyne.org | |
| 2021-10-16 | www.lockslaw.com | |
| 2021-09-30 | calautomotive.com | |
| 2021-09-30 | calsoft | |
| 2021-09-30 | calsoft.com | |
| 2021-09-25 | www.myyp.com | |
| 2021-09-09 | Reconservices.com | |
| 2021-09-09 | Capstoneins.com | |
| 2021-09-09 | neuro-logica.com | |
| 2021-09-09 | webstercare.com.au | |
| 2021-09-09 | www.crm.com | |
| 2021-09-09 | www.coreslab.com | |
| 2021-09-09 | www.emmawillard.org | |
| 2021-09-09 | pdsec.com | |
| 2021-09-09 | conferenceusa.com | |
| 2021-09-09 | sklarwilton.com | |
| 2021-09-09 | nsuship.co.jp | |
| 2021-09-09 | iRely LLC's Grand Failure | |
| 2021-09-09 | CD Project data | |
| 2021-09-09 | Victrongroup.com | |
| 2021-09-09 | Uptownbakers.com | |
| 2021-09-09 | Truckcentercompanies.com | |
| 2021-09-09 | Connelypartners.com | |
| 2021-09-09 | Wrgtexas.com | |
| 2021-09-09 | www.webstercare.com.au |
CONFIRMED ATTACKS
Payloadbin confirmed attacks: 1 verified incident
Ransomnews has verified 1 Payloadbin incident against named organisations, each corroborated by a public source such as a breach notification, regulatory filing or press report. All of them fall in February 2021. Poland accounts for 1 of them (100%). The most affected sector is technology, at 1 confirmed victim. A ransom payment was publicly confirmed in 0 cases and publicly refused in 1; the outcome is unrecorded in the remaining 0.
Confirmed victims by year
Most affected sectors
Most affected countries
Verified Payloadbin incidents
| Date | Organisation | Sector | Location | Records | Ransom paid | Source |
|---|---|---|---|---|---|---|
| February 2021 | CD PROJEKT RED | Technology | Warsaw, Poland | — | No | Source |
Claimed vs confirmed. The figures above the fold on this page come from Payloadbin's own leak-site postings and reflect what the operation claims. The table here is a separate evidence class: incidents Ransomnews verified against a public source. Confirmed counts are lower than claimed counts by design: most victims never disclose, and some leak-site listings are recycled, exaggerated or fabricated. Records and ransom figures are shown only where a named source disclosed them. See the full ransomware statistics or the Ransomtracker dataset.