{"id":13151,"date":"2026-05-26T10:03:46","date_gmt":"2026-05-26T10:03:46","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/05\/26\/payload-ransomware-uses-chacha20-and-curve25519-ecdh-to-encrypt-windows-files\/"},"modified":"2026-05-26T10:03:46","modified_gmt":"2026-05-26T10:03:46","slug":"payload-ransomware-uses-chacha20-and-curve25519-ecdh-to-encrypt-windows-files","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/05\/26\/payload-ransomware-uses-chacha20-and-curve25519-ecdh-to-encrypt-windows-files\/","title":{"rendered":"Payload Ransomware Uses ChaCha20 and Curve25519 ECDH to Encrypt Windows Files"},"content":{"rendered":"<p>    Payload Ransomware Uses ChaCha20 and Curve25519 ECDH to Encrypt Windows Files<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p class=\"wp-block-paragraph\">A dangerous new ransomware strain called Payload has been quietly building a global victim list since it first appeared in February 2026. <\/p>\n<p class=\"wp-block-paragraph\">The group launched its leak site with a high-profile target and has since expanded operations across Egypt, Mexico, Poland, and beyond. What makes this threat stand out is not just its reach, but the technical sophistication behind how it locks down victim files.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/b867795a-e881-4d53-8135-32254b26fc37\/Payload-Ransomware-Uses-ChaCha20-and-Curve25519-ECDH-to-Encrypt-Windows-Files.pdf?AWSAccessKeyId=ASIA2F3EMEYE54YE3XI7&amp;Signature=SkozHIM4L17F4L7YPsFq8y595oE%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEK3%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIAGg3rWmuYm3SPYhVhcLDZzN1m8U0H%2FHTbLNVsj07jLjAiBY%2BMQwCQ%2FQZM9c8tA%2FUqFsDQfSFPIe6xGoKa6DGVLttyrzBAh2EAEaDDY5OTc1MzMwOTcwNSIMEpuwh2kPh7UYxgXFKtAEiWqYkWt9UOi5Q5YX96p%2B586H%2BGogUZW3TvylaDt%2Ff0o8Y4GBu4fTFGxy%2BBWj1Bxw%2BraYMbvREVa8SJRvz9Bhf0VFGmr7hC364FXyMvFWGVjpLKTi5mH1Bo0KM4tRsUTaCyq9mMMkoQQLS8Hi8D6eV2HEROYF3nDocvG%2Fx5GVYGZKYzu1Q7GecTreEnLNOgcoeR%2BWClaOmZi%2BITtpr2lcq2bJOuKiV7y5louJyvaB6UVjeIvxxd8pdUltnC9f8zR5FGHbsopTgMpuXGZGgSfShADXmdm4noCwzrx8AB1yM%2BSboLcG724MUb0yUJ1Io6DYzPkcT%2BtDwYcZ18kRSLd%2BiqidNVHni%2FruRPrIfTTyCCQOi53dmLq78YI%2FqLxdEwq5SjsK0VpgmNByXyFu9fe4RO7oHjWlW2L0UNnTa1iv5LhmDVeLayesMmX1WGiyPSm0CWjFXG%2BFPyy1FRfh2RBHR0c8238JKRXOC51WMfTlo9mI4WPpIcWgFj0svsr9rqSteDz78lPidWrNDuEjs2iqykFw3ntQVmOfddddHn28naPEjL0JV95ecQzX%2BbknSW2qX%2FCHvGKiUh98ZQw%2FuTiWJpg%2FTSezfR%2B03MdP4VqoTuOW6bCht3o2Iw4c1ikJEL8MYQMwXWnqSBkMA9IusGdksyFMxyc%2F7c3zTMbTrYj%2BHSBEKHzOOVF5gO906TGH3iJd9Zpy1CLUzNmAuahSMM4mhS2OVeCTzA2Y7V2YUOZiD8TEa0hqTkMLdi9oZhWuCt15wILydJmuZAcNEel4Y0%2FuFDC2wdTQBjqZAXD1hdZ1K1LuozHE27xMhGNvFFYdsBUc5BHLR3vDNkbagCsRf%2BgwX2gLUJAcI2XbxjSU%2FiSIKec23i9v6ijBnXkjpm5%2FxVYAITF%2FJhzVrfb4IAGvOOUduNsVE2wDFlx9rUW8RnRKGAK4kLeEbezaBjFhfBz7aWmww0KP%2BAKhQoOzCWxTVyRL3WxcY2gWgLZ9EJRW39gOyJ4bzA%3D%3D&amp;Expires=1779772341\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\">Payload ransomware targets Windows systems and appends the \u201c.payload\u201d extension to every file it encrypts. Victims are greeted with a ransom note called RECOVER_payload.txt and given 240 hours to begin negotiations. <\/p>\n<p class=\"wp-block-paragraph\">By March 24, 2026, the group had already listed 50 victims on its leak site, ranging from real estate firms and logistics companies to manufacturers and technology providers.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/b867795a-e881-4d53-8135-32254b26fc37\/Payload-Ransomware-Uses-ChaCha20-and-Curve25519-ECDH-to-Encrypt-Windows-Files.pdf?AWSAccessKeyId=ASIA2F3EMEYE54YE3XI7&amp;Signature=SkozHIM4L17F4L7YPsFq8y595oE%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEK3%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIAGg3rWmuYm3SPYhVhcLDZzN1m8U0H%2FHTbLNVsj07jLjAiBY%2BMQwCQ%2FQZM9c8tA%2FUqFsDQfSFPIe6xGoKa6DGVLttyrzBAh2EAEaDDY5OTc1MzMwOTcwNSIMEpuwh2kPh7UYxgXFKtAEiWqYkWt9UOi5Q5YX96p%2B586H%2BGogUZW3TvylaDt%2Ff0o8Y4GBu4fTFGxy%2BBWj1Bxw%2BraYMbvREVa8SJRvz9Bhf0VFGmr7hC364FXyMvFWGVjpLKTi5mH1Bo0KM4tRsUTaCyq9mMMkoQQLS8Hi8D6eV2HEROYF3nDocvG%2Fx5GVYGZKYzu1Q7GecTreEnLNOgcoeR%2BWClaOmZi%2BITtpr2lcq2bJOuKiV7y5louJyvaB6UVjeIvxxd8pdUltnC9f8zR5FGHbsopTgMpuXGZGgSfShADXmdm4noCwzrx8AB1yM%2BSboLcG724MUb0yUJ1Io6DYzPkcT%2BtDwYcZ18kRSLd%2BiqidNVHni%2FruRPrIfTTyCCQOi53dmLq78YI%2FqLxdEwq5SjsK0VpgmNByXyFu9fe4RO7oHjWlW2L0UNnTa1iv5LhmDVeLayesMmX1WGiyPSm0CWjFXG%2BFPyy1FRfh2RBHR0c8238JKRXOC51WMfTlo9mI4WPpIcWgFj0svsr9rqSteDz78lPidWrNDuEjs2iqykFw3ntQVmOfddddHn28naPEjL0JV95ecQzX%2BbknSW2qX%2FCHvGKiUh98ZQw%2FuTiWJpg%2FTSezfR%2B03MdP4VqoTuOW6bCht3o2Iw4c1ikJEL8MYQMwXWnqSBkMA9IusGdksyFMxyc%2F7c3zTMbTrYj%2BHSBEKHzOOVF5gO906TGH3iJd9Zpy1CLUzNmAuahSMM4mhS2OVeCTzA2Y7V2YUOZiD8TEa0hqTkMLdi9oZhWuCt15wILydJmuZAcNEel4Y0%2FuFDC2wdTQBjqZAXD1hdZ1K1LuozHE27xMhGNvFFYdsBUc5BHLR3vDNkbagCsRf%2BgwX2gLUJAcI2XbxjSU%2FiSIKec23i9v6ijBnXkjpm5%2FxVYAITF%2FJhzVrfb4IAGvOOUduNsVE2wDFlx9rUW8RnRKGAK4kLeEbezaBjFhfBz7aWmww0KP%2BAKhQoOzCWxTVyRL3WxcY2gWgLZ9EJRW39gOyJ4bzA%3D%3D&amp;Expires=1779772341\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\">The group appears to focus on industries where downtime creates immediate financial pressure. Logistics and transportation firms sit high on its target list, as do construction and real estate companies in the MENA region. <\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/darkatlas.io\/blog\/behind-payload-in-depth-technical-analysis-of-payload-ransomware\" id=\"https:\/\/darkatlas.io\/blog\/behind-payload-in-depth-technical-analysis-of-payload-ransomware\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Dark Atlas\u00a0said in a report<\/a> shared with Cyber Security News (CSN) that they conducted an in-depth technical analysis and found the group to be technically mature, with a well-designed encryption engine and aggressive steps taken to prevent detection.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/b867795a-e881-4d53-8135-32254b26fc37\/Payload-Ransomware-Uses-ChaCha20-and-Curve25519-ECDH-to-Encrypt-Windows-Files.pdf?AWSAccessKeyId=ASIA2F3EMEYE54YE3XI7&amp;Signature=SkozHIM4L17F4L7YPsFq8y595oE%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEK3%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIAGg3rWmuYm3SPYhVhcLDZzN1m8U0H%2FHTbLNVsj07jLjAiBY%2BMQwCQ%2FQZM9c8tA%2FUqFsDQfSFPIe6xGoKa6DGVLttyrzBAh2EAEaDDY5OTc1MzMwOTcwNSIMEpuwh2kPh7UYxgXFKtAEiWqYkWt9UOi5Q5YX96p%2B586H%2BGogUZW3TvylaDt%2Ff0o8Y4GBu4fTFGxy%2BBWj1Bxw%2BraYMbvREVa8SJRvz9Bhf0VFGmr7hC364FXyMvFWGVjpLKTi5mH1Bo0KM4tRsUTaCyq9mMMkoQQLS8Hi8D6eV2HEROYF3nDocvG%2Fx5GVYGZKYzu1Q7GecTreEnLNOgcoeR%2BWClaOmZi%2BITtpr2lcq2bJOuKiV7y5louJyvaB6UVjeIvxxd8pdUltnC9f8zR5FGHbsopTgMpuXGZGgSfShADXmdm4noCwzrx8AB1yM%2BSboLcG724MUb0yUJ1Io6DYzPkcT%2BtDwYcZ18kRSLd%2BiqidNVHni%2FruRPrIfTTyCCQOi53dmLq78YI%2FqLxdEwq5SjsK0VpgmNByXyFu9fe4RO7oHjWlW2L0UNnTa1iv5LhmDVeLayesMmX1WGiyPSm0CWjFXG%2BFPyy1FRfh2RBHR0c8238JKRXOC51WMfTlo9mI4WPpIcWgFj0svsr9rqSteDz78lPidWrNDuEjs2iqykFw3ntQVmOfddddHn28naPEjL0JV95ecQzX%2BbknSW2qX%2FCHvGKiUh98ZQw%2FuTiWJpg%2FTSezfR%2B03MdP4VqoTuOW6bCht3o2Iw4c1ikJEL8MYQMwXWnqSBkMA9IusGdksyFMxyc%2F7c3zTMbTrYj%2BHSBEKHzOOVF5gO906TGH3iJd9Zpy1CLUzNmAuahSMM4mhS2OVeCTzA2Y7V2YUOZiD8TEa0hqTkMLdi9oZhWuCt15wILydJmuZAcNEel4Y0%2FuFDC2wdTQBjqZAXD1hdZ1K1LuozHE27xMhGNvFFYdsBUc5BHLR3vDNkbagCsRf%2BgwX2gLUJAcI2XbxjSU%2FiSIKec23i9v6ijBnXkjpm5%2FxVYAITF%2FJhzVrfb4IAGvOOUduNsVE2wDFlx9rUW8RnRKGAK4kLeEbezaBjFhfBz7aWmww0KP%2BAKhQoOzCWxTVyRL3WxcY2gWgLZ9EJRW39gOyJ4bzA%3D%3D&amp;Expires=1779772341\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\">The malware carries a mutex named \u201cMakeAmericaGreatAgain,\u201d which prevents multiple instances from running on the same machine. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg-DqSYFTW0EcClVvn5KKjKmB7XPHl-3sUNfpid-GMI0ZHOIpplJS1cYoACSiGRJ2VcD2MEZ2NWgbheNlFNICAPsttWWYIfkwBBIZn-JWz2DgXd6N3vloiQgcKJaLgYxhboFkTYhDTM0pd_oCuE7i_jKJG79vMgwOGcrDoepXsmsyQPMGjSvM8XMgeOQxI\/s16000\/Victims%2520by%2520country%2520%28Source%2520-%2520Dark%2520Atlas%29.webp?ssl=1\" alt=\"Victims by country (Source - Dark Atlas)\"><figcaption class=\"wp-element-caption\">Victims by country (Source \u2013 Dark Atlas)<\/figcaption><\/figure>\n<\/div>\n<p class=\"wp-block-paragraph\">Before encryption begins, it deletes Windows shadow copies, patches event-tracing functions in memory, clears Windows Event Logs, and terminates dozens of database, backup, and office processes. These steps leave victims with very little to fall back on.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/b867795a-e881-4d53-8135-32254b26fc37\/Payload-Ransomware-Uses-ChaCha20-and-Curve25519-ECDH-to-Encrypt-Windows-Files.pdf?AWSAccessKeyId=ASIA2F3EMEYE54YE3XI7&amp;Signature=SkozHIM4L17F4L7YPsFq8y595oE%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEK3%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIAGg3rWmuYm3SPYhVhcLDZzN1m8U0H%2FHTbLNVsj07jLjAiBY%2BMQwCQ%2FQZM9c8tA%2FUqFsDQfSFPIe6xGoKa6DGVLttyrzBAh2EAEaDDY5OTc1MzMwOTcwNSIMEpuwh2kPh7UYxgXFKtAEiWqYkWt9UOi5Q5YX96p%2B586H%2BGogUZW3TvylaDt%2Ff0o8Y4GBu4fTFGxy%2BBWj1Bxw%2BraYMbvREVa8SJRvz9Bhf0VFGmr7hC364FXyMvFWGVjpLKTi5mH1Bo0KM4tRsUTaCyq9mMMkoQQLS8Hi8D6eV2HEROYF3nDocvG%2Fx5GVYGZKYzu1Q7GecTreEnLNOgcoeR%2BWClaOmZi%2BITtpr2lcq2bJOuKiV7y5louJyvaB6UVjeIvxxd8pdUltnC9f8zR5FGHbsopTgMpuXGZGgSfShADXmdm4noCwzrx8AB1yM%2BSboLcG724MUb0yUJ1Io6DYzPkcT%2BtDwYcZ18kRSLd%2BiqidNVHni%2FruRPrIfTTyCCQOi53dmLq78YI%2FqLxdEwq5SjsK0VpgmNByXyFu9fe4RO7oHjWlW2L0UNnTa1iv5LhmDVeLayesMmX1WGiyPSm0CWjFXG%2BFPyy1FRfh2RBHR0c8238JKRXOC51WMfTlo9mI4WPpIcWgFj0svsr9rqSteDz78lPidWrNDuEjs2iqykFw3ntQVmOfddddHn28naPEjL0JV95ecQzX%2BbknSW2qX%2FCHvGKiUh98ZQw%2FuTiWJpg%2FTSezfR%2B03MdP4VqoTuOW6bCht3o2Iw4c1ikJEL8MYQMwXWnqSBkMA9IusGdksyFMxyc%2F7c3zTMbTrYj%2BHSBEKHzOOVF5gO906TGH3iJd9Zpy1CLUzNmAuahSMM4mhS2OVeCTzA2Y7V2YUOZiD8TEa0hqTkMLdi9oZhWuCt15wILydJmuZAcNEel4Y0%2FuFDC2wdTQBjqZAXD1hdZ1K1LuozHE27xMhGNvFFYdsBUc5BHLR3vDNkbagCsRf%2BgwX2gLUJAcI2XbxjSU%2FiSIKec23i9v6ijBnXkjpm5%2FxVYAITF%2FJhzVrfb4IAGvOOUduNsVE2wDFlx9rUW8RnRKGAK4kLeEbezaBjFhfBz7aWmww0KP%2BAKhQoOzCWxTVyRL3WxcY2gWgLZ9EJRW39gOyJ4bzA%3D%3D&amp;Expires=1779772341\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\">Organizations should monitor for RECOVER_payload.txt, the .payload file extension, and the log file written to ??C:payload.log. <a href=\"https:\/\/cybersecuritynews.com\/aligning-it-and-security-teams\/\" id=\"https:\/\/cybersecuritynews.com\/aligning-it-and-security-teams\/\">S<\/a><a href=\"https:\/\/cybersecuritynews.com\/aligning-it-and-security-teams\/\" id=\"108197\" target=\"_blank\" rel=\"noreferrer noopener\">ecurity teams should also watch for sudden termination of backup<\/a> and database services, as this often signals active ransomware deployment. <\/p>\n<p class=\"wp-block-paragraph\">Maintaining offline backups and protecting shadow copy services at the infrastructure level are critical steps in limiting the damage this threat can cause.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/b867795a-e881-4d53-8135-32254b26fc37\/Payload-Ransomware-Uses-ChaCha20-and-Curve25519-ECDH-to-Encrypt-Windows-Files.pdf?AWSAccessKeyId=ASIA2F3EMEYE54YE3XI7&amp;Signature=SkozHIM4L17F4L7YPsFq8y595oE%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEK3%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIAGg3rWmuYm3SPYhVhcLDZzN1m8U0H%2FHTbLNVsj07jLjAiBY%2BMQwCQ%2FQZM9c8tA%2FUqFsDQfSFPIe6xGoKa6DGVLttyrzBAh2EAEaDDY5OTc1MzMwOTcwNSIMEpuwh2kPh7UYxgXFKtAEiWqYkWt9UOi5Q5YX96p%2B586H%2BGogUZW3TvylaDt%2Ff0o8Y4GBu4fTFGxy%2BBWj1Bxw%2BraYMbvREVa8SJRvz9Bhf0VFGmr7hC364FXyMvFWGVjpLKTi5mH1Bo0KM4tRsUTaCyq9mMMkoQQLS8Hi8D6eV2HEROYF3nDocvG%2Fx5GVYGZKYzu1Q7GecTreEnLNOgcoeR%2BWClaOmZi%2BITtpr2lcq2bJOuKiV7y5louJyvaB6UVjeIvxxd8pdUltnC9f8zR5FGHbsopTgMpuXGZGgSfShADXmdm4noCwzrx8AB1yM%2BSboLcG724MUb0yUJ1Io6DYzPkcT%2BtDwYcZ18kRSLd%2BiqidNVHni%2FruRPrIfTTyCCQOi53dmLq78YI%2FqLxdEwq5SjsK0VpgmNByXyFu9fe4RO7oHjWlW2L0UNnTa1iv5LhmDVeLayesMmX1WGiyPSm0CWjFXG%2BFPyy1FRfh2RBHR0c8238JKRXOC51WMfTlo9mI4WPpIcWgFj0svsr9rqSteDz78lPidWrNDuEjs2iqykFw3ntQVmOfddddHn28naPEjL0JV95ecQzX%2BbknSW2qX%2FCHvGKiUh98ZQw%2FuTiWJpg%2FTSezfR%2B03MdP4VqoTuOW6bCht3o2Iw4c1ikJEL8MYQMwXWnqSBkMA9IusGdksyFMxyc%2F7c3zTMbTrYj%2BHSBEKHzOOVF5gO906TGH3iJd9Zpy1CLUzNmAuahSMM4mhS2OVeCTzA2Y7V2YUOZiD8TEa0hqTkMLdi9oZhWuCt15wILydJmuZAcNEel4Y0%2FuFDC2wdTQBjqZAXD1hdZ1K1LuozHE27xMhGNvFFYdsBUc5BHLR3vDNkbagCsRf%2BgwX2gLUJAcI2XbxjSU%2FiSIKec23i9v6ijBnXkjpm5%2FxVYAITF%2FJhzVrfb4IAGvOOUduNsVE2wDFlx9rUW8RnRKGAK4kLeEbezaBjFhfBz7aWmww0KP%2BAKhQoOzCWxTVyRL3WxcY2gWgLZ9EJRW39gOyJ4bzA%3D%3D&amp;Expires=1779772341\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<h2 id=\"h-payload-ransomware-uses-chacha20-and-curve25519-ecdh\" class=\"wp-block-heading\"><strong>Payload Ransomware Uses ChaCha20 and Curve25519 ECDH<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">Payload ransomware uses a per-file encryption approach that makes recovery without the operator\u2019s private key essentially impossible. For each file, the malware generates a fresh 32-byte private key and a 12-byte nonce using Windows\u2019 own CryptGenRandom function. <\/p>\n<p class=\"wp-block-paragraph\">It then runs a Curve25519 ECDH operation, combining the victim\u2019s temporary key with the operator\u2019s embedded public key to produce a shared secret used directly as the ChaCha20 key.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgJiBNjGsracwPgv1CQtWTDrEK8Jjw-rbRbPCAhMkbLvyXPLxQ5Hqe3WjZtcCYWIxVJuF8heOQCkPt-7WSce9otbxzMWQkok1MNS4w16GZ3bb0pI6eqwcNvag58c_b4u9K67O8RrQJ82rTDvlAlkIDHCNNZkqN-zRGx5trgbZPgAiZKX6IVuyE3p_gatYI\/s16000\/Mutex%2520and%2520Single-Instance%2520Check%2520%28Source%2520-%2520Dark%2520Atlas%29.webp?ssl=1\" alt=\"Mutex and Single-Instance Check (Source - Dark Atlas)\"><figcaption class=\"wp-element-caption\">Mutex and Single-Instance Check (Source \u2013 Dark Atlas)<\/figcaption><\/figure>\n<\/div>\n<p class=\"wp-block-paragraph\">Files are encrypted in one-megabyte chunks, and a 56-byte footer is written to the end of every file when the process completes. <\/p>\n<p class=\"wp-block-paragraph\">This footer holds the victim\u2019s temporary public key and the nonce, wrapped in RC4 encryption using the three-byte key \u201cFBI\u201d. The operator can use their private key to recover any file, but victims on their own have no path to decryption.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/b867795a-e881-4d53-8135-32254b26fc37\/Payload-Ransomware-Uses-ChaCha20-and-Curve25519-ECDH-to-Encrypt-Windows-Files.pdf?AWSAccessKeyId=ASIA2F3EMEYE54YE3XI7&amp;Signature=SkozHIM4L17F4L7YPsFq8y595oE%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEK3%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIAGg3rWmuYm3SPYhVhcLDZzN1m8U0H%2FHTbLNVsj07jLjAiBY%2BMQwCQ%2FQZM9c8tA%2FUqFsDQfSFPIe6xGoKa6DGVLttyrzBAh2EAEaDDY5OTc1MzMwOTcwNSIMEpuwh2kPh7UYxgXFKtAEiWqYkWt9UOi5Q5YX96p%2B586H%2BGogUZW3TvylaDt%2Ff0o8Y4GBu4fTFGxy%2BBWj1Bxw%2BraYMbvREVa8SJRvz9Bhf0VFGmr7hC364FXyMvFWGVjpLKTi5mH1Bo0KM4tRsUTaCyq9mMMkoQQLS8Hi8D6eV2HEROYF3nDocvG%2Fx5GVYGZKYzu1Q7GecTreEnLNOgcoeR%2BWClaOmZi%2BITtpr2lcq2bJOuKiV7y5louJyvaB6UVjeIvxxd8pdUltnC9f8zR5FGHbsopTgMpuXGZGgSfShADXmdm4noCwzrx8AB1yM%2BSboLcG724MUb0yUJ1Io6DYzPkcT%2BtDwYcZ18kRSLd%2BiqidNVHni%2FruRPrIfTTyCCQOi53dmLq78YI%2FqLxdEwq5SjsK0VpgmNByXyFu9fe4RO7oHjWlW2L0UNnTa1iv5LhmDVeLayesMmX1WGiyPSm0CWjFXG%2BFPyy1FRfh2RBHR0c8238JKRXOC51WMfTlo9mI4WPpIcWgFj0svsr9rqSteDz78lPidWrNDuEjs2iqykFw3ntQVmOfddddHn28naPEjL0JV95ecQzX%2BbknSW2qX%2FCHvGKiUh98ZQw%2FuTiWJpg%2FTSezfR%2B03MdP4VqoTuOW6bCht3o2Iw4c1ikJEL8MYQMwXWnqSBkMA9IusGdksyFMxyc%2F7c3zTMbTrYj%2BHSBEKHzOOVF5gO906TGH3iJd9Zpy1CLUzNmAuahSMM4mhS2OVeCTzA2Y7V2YUOZiD8TEa0hqTkMLdi9oZhWuCt15wILydJmuZAcNEel4Y0%2FuFDC2wdTQBjqZAXD1hdZ1K1LuozHE27xMhGNvFFYdsBUc5BHLR3vDNkbagCsRf%2BgwX2gLUJAcI2XbxjSU%2FiSIKec23i9v6ijBnXkjpm5%2FxVYAITF%2FJhzVrfb4IAGvOOUduNsVE2wDFlx9rUW8RnRKGAK4kLeEbezaBjFhfBz7aWmww0KP%2BAKhQoOzCWxTVyRL3WxcY2gWgLZ9EJRW39gOyJ4bzA%3D%3D&amp;Expires=1779772341\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\">The ransomware supports three speed modes, automatically choosing between AVX2, SSE2, and a standard scalar path based on the victim\u2019s processor. It also uses direct Windows NT API calls rather than standard user-mode functions, helping it <a href=\"https:\/\/cybersecuritynews.com\/hackers-deliver-malware-via-browser-extensions-legitimate-tools\/\" id=\"97153\" target=\"_blank\" rel=\"noreferrer noopener\">bypass security tools that monitor higher-level activity<\/a>.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/b867795a-e881-4d53-8135-32254b26fc37\/Payload-Ransomware-Uses-ChaCha20-and-Curve25519-ECDH-to-Encrypt-Windows-Files.pdf?AWSAccessKeyId=ASIA2F3EMEYE54YE3XI7&amp;Signature=SkozHIM4L17F4L7YPsFq8y595oE%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEK3%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIAGg3rWmuYm3SPYhVhcLDZzN1m8U0H%2FHTbLNVsj07jLjAiBY%2BMQwCQ%2FQZM9c8tA%2FUqFsDQfSFPIe6xGoKa6DGVLttyrzBAh2EAEaDDY5OTc1MzMwOTcwNSIMEpuwh2kPh7UYxgXFKtAEiWqYkWt9UOi5Q5YX96p%2B586H%2BGogUZW3TvylaDt%2Ff0o8Y4GBu4fTFGxy%2BBWj1Bxw%2BraYMbvREVa8SJRvz9Bhf0VFGmr7hC364FXyMvFWGVjpLKTi5mH1Bo0KM4tRsUTaCyq9mMMkoQQLS8Hi8D6eV2HEROYF3nDocvG%2Fx5GVYGZKYzu1Q7GecTreEnLNOgcoeR%2BWClaOmZi%2BITtpr2lcq2bJOuKiV7y5louJyvaB6UVjeIvxxd8pdUltnC9f8zR5FGHbsopTgMpuXGZGgSfShADXmdm4noCwzrx8AB1yM%2BSboLcG724MUb0yUJ1Io6DYzPkcT%2BtDwYcZ18kRSLd%2BiqidNVHni%2FruRPrIfTTyCCQOi53dmLq78YI%2FqLxdEwq5SjsK0VpgmNByXyFu9fe4RO7oHjWlW2L0UNnTa1iv5LhmDVeLayesMmX1WGiyPSm0CWjFXG%2BFPyy1FRfh2RBHR0c8238JKRXOC51WMfTlo9mI4WPpIcWgFj0svsr9rqSteDz78lPidWrNDuEjs2iqykFw3ntQVmOfddddHn28naPEjL0JV95ecQzX%2BbknSW2qX%2FCHvGKiUh98ZQw%2FuTiWJpg%2FTSezfR%2B03MdP4VqoTuOW6bCht3o2Iw4c1ikJEL8MYQMwXWnqSBkMA9IusGdksyFMxyc%2F7c3zTMbTrYj%2BHSBEKHzOOVF5gO906TGH3iJd9Zpy1CLUzNmAuahSMM4mhS2OVeCTzA2Y7V2YUOZiD8TEa0hqTkMLdi9oZhWuCt15wILydJmuZAcNEel4Y0%2FuFDC2wdTQBjqZAXD1hdZ1K1LuozHE27xMhGNvFFYdsBUc5BHLR3vDNkbagCsRf%2BgwX2gLUJAcI2XbxjSU%2FiSIKec23i9v6ijBnXkjpm5%2FxVYAITF%2FJhzVrfb4IAGvOOUduNsVE2wDFlx9rUW8RnRKGAK4kLeEbezaBjFhfBz7aWmww0KP%2BAKhQoOzCWxTVyRL3WxcY2gWgLZ9EJRW39gOyJ4bzA%3D%3D&amp;Expires=1779772341\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<h2 id=\"h-anti-forensics-behavior-and-evasion-techniques\" class=\"wp-block-heading\"><strong>Anti-Forensics Behavior and Evasion Techniques<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">One of the most alarming aspects of Payload ransomware is how aggressively it erases its own tracks. When the bypass-etw flag is active, the <a href=\"https:\/\/cybersecuritynews.com\/ivanti-patches-multiple-vulnerabilities\/\" id=\"149798\" target=\"_blank\" rel=\"noreferrer noopener\">malware patches four key event-tracing functions<\/a> inside Windows\u2019 ntdll library, silencing the system\u2019s ability to log what the ransomware is doing.<\/p>\n<p class=\"wp-block-paragraph\"> Combined with the deletion of all shadow copies before encryption begins, defenders are left with very little forensic evidence after an attack.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi3beUzYd-HIrSaV8b7XZ47M449cD8tO3qKxU0C-9t-1I8mN_QT5qKmAwcq7yFeAsndM9Z2i2YPP8yJ5ogLdAwzhx2wpdiOjNP2aqbfVAfm2Y1DBEbfRyI4_xKYpr55eVJ-gcDLW99cMSW8KH6q5reB0piZZBQdZaN6z9HUdu256jVZb5t2cQefZbvAox4\/s16000\/Per-File%2520Key-Handoff%2520Design%2520%28Source%2520-%2520Dark%2520Atlas%29.webp?ssl=1\" alt=\"Per-File Key-Handoff Design (Source - Dark Atlas)\"><figcaption class=\"wp-element-caption\">Per-File Key-Handoff Design (Source \u2013 Dark Atlas)<\/figcaption><\/figure>\n<\/div>\n<p class=\"wp-block-paragraph\">The ransomware loads the Windows event log API at runtime and clears every available channel, including Application, System, and Security logs. <\/p>\n<p class=\"wp-block-paragraph\">It terminates over 30 processes and stops more than 40 services before locking files, targeting everything from SQL databases to Veeam and Acronis backup solutions. Once those protections are removed, encryption runs without interference.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/b867795a-e881-4d53-8135-32254b26fc37\/Payload-Ransomware-Uses-ChaCha20-and-Curve25519-ECDH-to-Encrypt-Windows-Files.pdf?AWSAccessKeyId=ASIA2F3EMEYE54YE3XI7&amp;Signature=SkozHIM4L17F4L7YPsFq8y595oE%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEK3%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIAGg3rWmuYm3SPYhVhcLDZzN1m8U0H%2FHTbLNVsj07jLjAiBY%2BMQwCQ%2FQZM9c8tA%2FUqFsDQfSFPIe6xGoKa6DGVLttyrzBAh2EAEaDDY5OTc1MzMwOTcwNSIMEpuwh2kPh7UYxgXFKtAEiWqYkWt9UOi5Q5YX96p%2B586H%2BGogUZW3TvylaDt%2Ff0o8Y4GBu4fTFGxy%2BBWj1Bxw%2BraYMbvREVa8SJRvz9Bhf0VFGmr7hC364FXyMvFWGVjpLKTi5mH1Bo0KM4tRsUTaCyq9mMMkoQQLS8Hi8D6eV2HEROYF3nDocvG%2Fx5GVYGZKYzu1Q7GecTreEnLNOgcoeR%2BWClaOmZi%2BITtpr2lcq2bJOuKiV7y5louJyvaB6UVjeIvxxd8pdUltnC9f8zR5FGHbsopTgMpuXGZGgSfShADXmdm4noCwzrx8AB1yM%2BSboLcG724MUb0yUJ1Io6DYzPkcT%2BtDwYcZ18kRSLd%2BiqidNVHni%2FruRPrIfTTyCCQOi53dmLq78YI%2FqLxdEwq5SjsK0VpgmNByXyFu9fe4RO7oHjWlW2L0UNnTa1iv5LhmDVeLayesMmX1WGiyPSm0CWjFXG%2BFPyy1FRfh2RBHR0c8238JKRXOC51WMfTlo9mI4WPpIcWgFj0svsr9rqSteDz78lPidWrNDuEjs2iqykFw3ntQVmOfddddHn28naPEjL0JV95ecQzX%2BbknSW2qX%2FCHvGKiUh98ZQw%2FuTiWJpg%2FTSezfR%2B03MdP4VqoTuOW6bCht3o2Iw4c1ikJEL8MYQMwXWnqSBkMA9IusGdksyFMxyc%2F7c3zTMbTrYj%2BHSBEKHzOOVF5gO906TGH3iJd9Zpy1CLUzNmAuahSMM4mhS2OVeCTzA2Y7V2YUOZiD8TEa0hqTkMLdi9oZhWuCt15wILydJmuZAcNEel4Y0%2FuFDC2wdTQBjqZAXD1hdZ1K1LuozHE27xMhGNvFFYdsBUc5BHLR3vDNkbagCsRf%2BgwX2gLUJAcI2XbxjSU%2FiSIKec23i9v6ijBnXkjpm5%2FxVYAITF%2FJhzVrfb4IAGvOOUduNsVE2wDFlx9rUW8RnRKGAK4kLeEbezaBjFhfBz7aWmww0KP%2BAKhQoOzCWxTVyRL3WxcY2gWgLZ9EJRW39gOyJ4bzA%3D%3D&amp;Expires=1779772341\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\">The Payload should be tracked as an emerging ransomware operation with international ambitions. The report noted that monitoring its leak site, victim patterns, and future code changes will be essential as the group continues to grow.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/b867795a-e881-4d53-8135-32254b26fc37\/Payload-Ransomware-Uses-ChaCha20-and-Curve25519-ECDH-to-Encrypt-Windows-Files.pdf?AWSAccessKeyId=ASIA2F3EMEYE54YE3XI7&amp;Signature=SkozHIM4L17F4L7YPsFq8y595oE%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEK3%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIAGg3rWmuYm3SPYhVhcLDZzN1m8U0H%2FHTbLNVsj07jLjAiBY%2BMQwCQ%2FQZM9c8tA%2FUqFsDQfSFPIe6xGoKa6DGVLttyrzBAh2EAEaDDY5OTc1MzMwOTcwNSIMEpuwh2kPh7UYxgXFKtAEiWqYkWt9UOi5Q5YX96p%2B586H%2BGogUZW3TvylaDt%2Ff0o8Y4GBu4fTFGxy%2BBWj1Bxw%2BraYMbvREVa8SJRvz9Bhf0VFGmr7hC364FXyMvFWGVjpLKTi5mH1Bo0KM4tRsUTaCyq9mMMkoQQLS8Hi8D6eV2HEROYF3nDocvG%2Fx5GVYGZKYzu1Q7GecTreEnLNOgcoeR%2BWClaOmZi%2BITtpr2lcq2bJOuKiV7y5louJyvaB6UVjeIvxxd8pdUltnC9f8zR5FGHbsopTgMpuXGZGgSfShADXmdm4noCwzrx8AB1yM%2BSboLcG724MUb0yUJ1Io6DYzPkcT%2BtDwYcZ18kRSLd%2BiqidNVHni%2FruRPrIfTTyCCQOi53dmLq78YI%2FqLxdEwq5SjsK0VpgmNByXyFu9fe4RO7oHjWlW2L0UNnTa1iv5LhmDVeLayesMmX1WGiyPSm0CWjFXG%2BFPyy1FRfh2RBHR0c8238JKRXOC51WMfTlo9mI4WPpIcWgFj0svsr9rqSteDz78lPidWrNDuEjs2iqykFw3ntQVmOfddddHn28naPEjL0JV95ecQzX%2BbknSW2qX%2FCHvGKiUh98ZQw%2FuTiWJpg%2FTSezfR%2B03MdP4VqoTuOW6bCht3o2Iw4c1ikJEL8MYQMwXWnqSBkMA9IusGdksyFMxyc%2F7c3zTMbTrYj%2BHSBEKHzOOVF5gO906TGH3iJd9Zpy1CLUzNmAuahSMM4mhS2OVeCTzA2Y7V2YUOZiD8TEa0hqTkMLdi9oZhWuCt15wILydJmuZAcNEel4Y0%2FuFDC2wdTQBjqZAXD1hdZ1K1LuozHE27xMhGNvFFYdsBUc5BHLR3vDNkbagCsRf%2BgwX2gLUJAcI2XbxjSU%2FiSIKec23i9v6ijBnXkjpm5%2FxVYAITF%2FJhzVrfb4IAGvOOUduNsVE2wDFlx9rUW8RnRKGAK4kLeEbezaBjFhfBz7aWmww0KP%2BAKhQoOzCWxTVyRL3WxcY2gWgLZ9EJRW39gOyJ4bzA%3D%3D&amp;Expires=1779772341\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\" id=\"h-indicators-of-compromise-iocs\"><strong>Indicators of Compromise (IoCs):-<\/strong><\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th class=\"has-text-align-left\" data-align=\"left\">Type<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Indicator<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Description<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>MD5<\/td>\n<td>E0FD8FF6D39E4C11BDAF860C35FD8DC0<\/td>\n<td>Payload ransomware sample hash<\/td>\n<\/tr>\n<tr>\n<td>SHA1<\/td>\n<td>DDE1B933AAD33C5D96C2E45AD46434A200DC46A6<\/td>\n<td>Payload ransomware sample hash<\/td>\n<\/tr>\n<tr>\n<td>SHA256<\/td>\n<td>1CA67AF90400EE6CBBD42175293274A0F5DC05315096CB2E214E4BFE12FFB71F<\/td>\n<td>Payload ransomware sample hash<\/td>\n<\/tr>\n<tr>\n<td>Mutex<\/td>\n<td>MakeAmericaGreatAgain<\/td>\n<td>Ransomware single-instance mutex<\/td>\n<\/tr>\n<tr>\n<td>File Extension<\/td>\n<td>.payload<\/td>\n<td>Extension appended to encrypted files<\/td>\n<\/tr>\n<tr>\n<td>File Name<\/td>\n<td>RECOVER_payload.txt<\/td>\n<td>Ransom note dropped in affected directories<\/td>\n<\/tr>\n<tr>\n<td>Recovery Label<\/td>\n<td>g:payload<\/td>\n<td>Key-handoff label written to recovery.ini<\/td>\n<\/tr>\n<tr>\n<td>Log File Path<\/td>\n<td>??C:payload.log<\/td>\n<td>Operator activity log written during execution<\/td>\n<\/tr>\n<tr>\n<td>VSS Deletion Command<\/td>\n<td>\/c vssadmin.exe delete shadows \/all \/quiet<\/td>\n<td>Shadow copy destruction command<\/td>\n<\/tr>\n<tr>\n<td>Tor Leak Site<\/td>\n<td>payloadrz5yw227brtbvdqpnlhq3rdcdekdnn3rgucbcdeawq2v6vuyd[.]onion<\/td>\n<td>Payload ransomware group\u2019s victim blog<\/td>\n<\/tr>\n<tr>\n<td>Tor Negotiation Portal<\/td>\n<td>payloadynyvabjacbun4uwhmxc7yvdzorycslzmnleguxjn7glahsvqd[.]onion<\/td>\n<td>Ransom negotiation portal<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p class=\"wp-block-paragraph\"><strong>Note:<\/strong>\u00a0<em>IP addresses and domains are intentionally defanged (e.g.,\u00a0<\/em><code><em>[.]<\/em><\/code><em>) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM<\/em>.<\/p>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)\"><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in<\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong> <strong><strong><a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener\">Google<\/a><\/strong><\/strong>.<\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/payload-ransomware-uses-chacha20\/\">Payload Ransomware Uses ChaCha20 and Curve25519 ECDH to Encrypt Windows Files<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/payload-ransomware-uses-chacha20\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Payload Ransomware Uses ChaCha20 and Curve25519 ECDH to Encrypt Windows Files A dangerous new ransomware strain called Payload has been quietly building a global victim list since it first appeared in February 2026. The group launched its leak site with a high-profile target and has since expanded operations across Egypt, Mexico, Poland, and beyond. What [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-13151","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13151"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=13151"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13151\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=13151"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=13151"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=13151"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}