Skip to content
PAYLOAD ransomware hijacks Windows Group Policy in encryption

PAYLOAD ransomware hijacks Windows Group Policy in encryption

Cyberinsider • September 22, 2026

A PAYLOAD ransomware incident weaponized Microsoft Active Directory Group Policy to disrupt an organization’s Windows computers without deploying ransomware or encrypting files.

Instead, the attackers used the company’s own administration infrastructure to display ransom notes, change wallpapers, deactivate local administrator accounts, and turn off Windows Firewall across the network.

Kaspersky’s Global Emergency Response Team (GERT) investigated the attack after an incident at an unnamed manufacturing organization in the Middle East. Kaspersky researchers Ahmad Zaidi Said and Elsayed Elrefaei said the attackers first accessed the network on April 11 using a compromised domain account through the company’s FortiGate SSL VPN.

Because PAYLOAD was linked at the root of the company’s domain, its settings could reach virtually every domain-joined Windows workstation. The attackers used it to distribute a README-payload.txt ransom note, replace desktop and lock-screen images with payload.jpg, display a ransom message at login, and disable the built-in local administrator account.

A second GPO named “win Firewall Off” disabled Windows Firewall across domain, private, and public profiles.

However, the changes did not appear immediately. Kaspersky found that the malicious policies had reached endpoints on April 13 but remained largely dormant until computers restarted the following day. When employees began rebooting their systems on April 14, the policies took effect across the organization and caused widespread disruption.

The attackers also exfiltrated data from file servers and other systems, and later published the stolen information on the dark web. Kaspersky also found a PAYLOAD ransomware variant targeting ESXi servers, but found no evidence that Windows files were encrypted.

Forensic examination found no malicious Windows executable, persistence mechanism, or active malware process. According to Kaspersky, the attack effectively lived inside Active Directory, allowing it to bypass security monitoring focused primarily on suspicious files and processes.

The incident highlights the risks of attackers gaining control of Group Policy, which ransomware operations, including Ryuk, LockBit, and BlackCat, have also abused for network-wide deployment.

Kaspersky recommends that organizations closely monitor the creation and modification of GPOs, particularly policies linked at the domain level, and monitor SYSVOL for unexpected files or configuration changes. Companies should also enforce phishing-resistant MFA for VPN access, restrict who can create and link Group Policies, centrally collect Active Directory audit logs, and protect privileged administrator accounts.

Organizations responding to this type of attack should remove malicious Group Policies from domain controllers before cleaning individual computers, or the compromised policies can be reapplied during the Group Policy refresh.

ZTE SmartLife flaws allow account takeover without reset code

WordPress “wp2shell” attacks stole 18,000 government records

Ireland fines Google €403 million over location data processing

WordPress Click2Shell flaw enables RCE after one admin click

Spain blocks anonymous service Archive.today and all mirror domains

Google Gemini hacked three firms after test sandbox exposed web access

Bill specializes in explaining complex technical topics to a non-technical audience. In his 30+ year career, he has covered many of the technological advances that shape our lives. Today, Bill uses those skills to help people protect their privacy and security against the ever-growing assaults on both.

Extracted Entities

Attack Types (1)

Countries (2)

Industries (1)

Ransomware Groups (3)

Vulnerabilities (1)