Payment
- First seen
- 2019-05-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Last IoC activity
- 2026-05-09 16:03:22
- Profile updated
- 2026-07-07 16:17:17
Targeted industries: financial-services retail-and-hospitality healthcare-and-pharmaceutical
Context
Payment is a ransomware family that encrypts victims' files and demands payment for decryption keys, primarily targeting sectors likely to yield higher ransoms.
Detection coverage
- 1 YARA rules
Used by threat actors
- Healthcare Social Engineering & Payment Diversion Activity (campaign)
- PaperCut Vulnerability Exploitation (campaign)
Detection rules
- SIGNATURE_BASE_MAL_DLL_Chrome_App_Bound_Encryption_Decryption_May25 (yara-rule)