www.kaspersky.com PAYLOAD Ransomware Exploits Active Directory for Disruption
Article Content
- •Attackers exploited Active Directory Group Policy to deliver ransom notes without encryption.
- •No malware was found on workstations, highlighting a new method of ransomware delivery.
- •Data exfiltration occurred, with sensitive information published on the dark web.
In April 2026, Kaspersky's Global Emergency Response Team responded to a ransomware incident at a manufacturing organization in the Middle East. Attackers gained domain-admin-equivalent control through a compromised account and created a malicious Group Policy Object (GPO) named PAYLOAD at the domain root. This GPO pushed ransom notes, altered desktop wallpapers, enforced a ransom logon banner, and disabled local administrator accounts across all domain-joined Windows systems, all without encrypting files or deploying malware. A second GPO disabled Windows Firewall. Data exfiltration occurred, with sensitive information later published on the dark web. The attack exemplifies a trend of encryptionless extortion, leveraging trusted enterprise infrastructure for operational disruption. No malicious binaries or processes were found on affected workstations, indicating a novel attack vector that evades traditional detection methods.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Storm-0501, Apt29 and Cobalt Strike in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Spring Ring: Coordinated Vishing Campaign Exploits Microsoft Teams Between January and April 2026, a coordinated voice phishing campaign named Spring Ring targeted over 150 employees across more than 10 companies using fake IT support accounts on Microsoft Teams. Attackers registered external Teams tenants with names resembling internal IT departments to gain trust. The campaign…
Russia's AI-Driven Cyber Espionage Targets Ukraine and Europe A Russian-linked hacking group, identified as GTG-20006, has utilized Anthropic's Claude AI to automate cyber espionage against over 20 organizations, primarily in Ukraine and Europe. The group targeted Ukrainian government officials, military personnel, and drone manufacturers through sophisticated phishing and…