---
title: "The Ransomware Gang That Rents a Tiny Apartment Inside Your PC"
description: "A forensic writeup reconstructs PayoutsKing’s trick of hiding a whole virtual machine inside the machine it is robbing"
author: "Tomasz Idle"
published: 2026-09-27T04:34:03.655Z
modified: 2026-09-27T05:09:42Z
url: https://rews.cc/a/the-ransomware-gang-that-rents-a-tiny-apartment-inside-your--ff9264
language: en
tags: ["cybersecurity", "ransomware", "forensics", "wmi", "qemu", "tech"]
publisher: "Rews (https://rews.cc)"
---

# The Ransomware Gang That Rents a Tiny Apartment Inside Your PC

*A forensic writeup reconstructs PayoutsKing’s trick of hiding a whole virtual machine inside the machine it is robbing*

By Tomasz Idle · September 27, 2026 · https://rews.cc/a/the-ransomware-gang-that-rents-a-tiny-apartment-inside-your--ff9264

## In brief

- SCRT’s Insomni’Hack 2026 forensics challenge reproduces real PayoutsKing intrusions; 16 teams solved it
- PayoutsKing enters via phishing, exposed services and flaws like CVE-2025-55182 and CVE-2025-59287, then exfiltrates hundreds of GB to TBs
- The crew now hides a QEMU-booted Alpine micro-VM on victim machines as a jump box and exfiltration collector
- WMI persistence disguised as an Oracle recovery tool launched the encrypted VM and typed its LUKS password
- Files arriving over SSH on port 22022 were rcloned to a C2 and deleted once inotify saw the writes finish

Most burglars want to get out of your house as quickly as they got in. PayoutsKing is different. The extortion crew likes to stay, and lately, according to incident responders at the Swiss security firm SCRT, it has taken to building a small second home inside the victim’s computer: a virtual machine, booted up by an ordinary copy of the QEMU emulator, from which it can conduct the business of your ruin in peace, shielded from whatever antivirus guards the main premises.

In a writeup published this week, SCRT’s team walks through *Golden Payout*, a forensics challenge it built for the Insomni’Hack 2026 competition, which 16 teams managed to solve. The scenario was fiction — sensitive documents surfacing on a darknet leak site, outbound traffic traced back to a database administrator’s workstation — but heavily seasoned with fact. The challenge, the authors say, reproduces techniques observed in real PayoutsKing intrusions, with a few extra flourishes because, in the authors’ telling, the original case was almost disappointingly straightforward.

The real crew’s résumé, as SCRT summarizes it, is thorough. Initial access comes from phishing, exposed services like RDP, VPNs and web apps, reused stolen credentials or critical flaws such as CVE-2025-55182 in React2Shell and CVE-2025-59287 in WSUS. The intruders then pivot over SMB or RDP, hoovering up credentials from LSASS memory, the SAM hive and crash dumps, with the NTDS.DIT domain database as the jackpot. Security tools, logging and backup agents get disabled along the way. The point of the exercise is exfiltration — hundreds of gigabytes, sometimes terabytes — and in roughly half of cases a ChaCha8-based ransomware renames every encrypted file with a .payoutsking extension. A ransom demand on a TOR negotiation portal always follows, with Tox and PGP as backup channels. The group, SCRT notes, prides itself on not franchising its brand as ransomware-as-a-service. Even criminals have standards, or at least a marketing department.

The recent twist, and the heart of the challenge, is a shift in persistence. For the past few months PayoutsKing has been hiding a QCOW micro-VM on victim machines, run by a portable QEMU emulator, and using it as a reverse-tunneling gateway and internal jump box. Other compromised hosts on the network then scp whatever files they find to this enslaved machine over port 22022, into a directory called /var/analyze\_schema, and the little tenant handles the final exfiltration to the command-and-control server. The workstation, in other words, becomes a mail-forwarding service that doesn’t know it is one.

Fitting this challenge back together begins conventionally: mount the E01 disk image, run Autoruns, look around. There is little to see, on purpose. The Security log was cleared — in fact all logs were cleared — and the PowerShell history is empty. The one honest witness is Windows Prefetch, which recorded the emulator’s execution; the challenge author concedes that would have made things too easy, and one senses a certain sympathy for the forensic analyst’s lot.

The actual persistence is quieter. A WMI event subscription with the soothing name OracleRecoveryFilter polls a system performance class every five minutes, and a matching OracleRecoveryConsumer runs a PowerShell script each time the filter fires. This, the authors note, is not classic PayoutsKing, which tends to be noisier and favors plain scheduled tasks; subscription-based WMI persistence is more of a hallmark of Russian-style operations, they write, name-checking APT29 and APT28, with appropriately hedged guesses about which intelligence services those may or may not answer to.

The script itself lives at \\ProgramData\\Oracle\\Diag\\Recovery\\OracleDB-Recovery.ps1 and plays the part of an Oracle utility. It fetches a value called Seed from the registry and de-obfuscates it character by character with an 11-position rotation over a custom alphabet. Then it builds the launch command for an executable named ora\_db\_recovery.exe — which is not a database repair tool at all but QEMU: 256 MB of RAM, an image file named ora\_sys\_01.db mounted as the hard drive, host port 22022 forwarded to port 22 inside the guest, and the whole thing started invisibly. The script then waits sixty seconds, long enough for the tiny Alpine Linux guest to reach a login, and types the de-obfuscated string straight into it — because the virtual disk is LUKS-encrypted, and someone has to enter the password at boot. A machine, automatically doing the one thing machines supposedly can’t do for you.

Here the author admits to artistic license: the real PayoutsKing VMs were not encrypted and could simply be mounted, so for the competition a LUKS layer was added to make the analysts earn their badge. De-rotating the Seed yields the passphrase — M4nn3rsM4k3thM4n, *manners maketh man*, a sentiment the gang’s victims would presumably contest. From there the forensics is plumbing: expose the QCOW image through qemu-nbd on a Kali WSL machine, politely ask the kernel to re-read the partition table it never scanned, unlock the LUKS volume, activate the volume groups and mount.

Inside, the tenant’s business model is laid out with corporate clarity. A startup script disguised as yet another Oracle utility listens for finished file writes in /var/analyze\_schema using inotify; when a file completes, rclone pushes it to a command-and-control server — here an IP belonging to Google Cloud — and deletes the local copy. The enslaved host listens on port 22022, QEMU redirects the traffic to port 22 in the guest, and the stolen data flows outward. The rclone credentials are themselves obfuscated, but only cosmetically: rclone encrypts stored passwords with a fixed key in a simple reversible scheme, which can be unwound with a bit of cryptography or, for those allergic to cryptography, simply by feeding the config file to rclone’s own reveal command. Out falls the flag.

> As the flag suggests, QEMU is indeed a formidable weapon, whether in the hands of the good guys or the bad guys.

That is the unobvious lesson of Golden Payout. The emulator, the micro-VM, the sync tool, even the fake Oracle branding — none of it is exotic malware. It is the white-hat toolkit, running on company time for the other side, in a guest room the host never knew it had. The difference between a systems administrator and a ransomware crew is narrowing to a question of who typed the password.
