Technical analysis of Payload ransomware, covering .payload encryption, ChaCha20, Curve25519 ECDH, ransom note recovery, and anti-forensics. Key Takeaways - Payload ransomware first appeared publicly in February 2026 and quickly showed a global victim footprint across Egypt, Mexico, Poland, and other regions. - As of 24 March 2026, the group had listed 50 victims on its leak site. - The ransomware encrypts files using ChaCha20, with a fresh Curve25519 ECDH key exchange per file. - Encrypted files receive the .payload extension and include a 56-byte RC4-encrypted footer. - The sample drops RECOVER_payload.txt, writes recovery data to recovery.ini, and uses strong anti-forensics techniques. - Anti-forensics behavior includes ETW memory patching, VSS shadow copy deletion, Windows Event Log clearing, and targeted termination of processes and services