Payment

First seen
2019-05-01 00:00:00
Malware type
ransomware
Family
Malware family
Last IoC activity
2026-05-09 16:03:22
Profile updated
2026-07-07 16:17:17

Targeted industries: financial-services retail-and-hospitality healthcare-and-pharmaceutical

Context

Payment is a ransomware family that encrypts victims' files and demands payment for decryption keys, primarily targeting sectors likely to yield higher ransoms.

Detection coverage

  • 1 YARA rules

Used by threat actors

  • Healthcare Social Engineering & Payment Diversion Activity (campaign)
  • PaperCut Vulnerability Exploitation (campaign)

Detection rules

  • SIGNATURE_BASE_MAL_DLL_Chrome_App_Bound_Encryption_Decryption_May25 (yara-rule)