Skip to content
PAYLOAD Ransomware Exploits Active Directory for Disruption

PAYLOAD Ransomware Exploits Active Directory for Disruption

First seen 21 Sep 2026, 18:21 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 21, 2026 at 18:54 UTC
  • Attackers exploited Active Directory Group Policy to deliver ransom notes without encryption.
  • No malware was found on workstations, highlighting a new method of ransomware delivery.
  • Data exfiltration occurred, with sensitive information published on the dark web.

In April 2026, Kaspersky's Global Emergency Response Team responded to a ransomware incident at a manufacturing organization in the Middle East. Attackers gained domain-admin-equivalent control through a compromised account and created a malicious Group Policy Object (GPO) named PAYLOAD at the domain root. This GPO pushed ransom notes, altered desktop wallpapers, enforced a ransom logon banner, and disabled local administrator accounts across all domain-joined Windows systems, all without encrypting files or deploying malware. A second GPO disabled Windows Firewall. Data exfiltration occurred, with sensitive information later published on the dark web. The attack exemplifies a trend of encryptionless extortion, leveraging trusted enterprise infrastructure for operational disruption. No malicious binaries or processes were found on affected workstations, indicating a novel attack vector that evades traditional detection methods.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-04-01
Initial access gained
Attackers compromised a valid account via FortiGate SSL VPN to gain access.
Securelist
2026-04-01
Malicious GPO created
A GPO named PAYLOAD was created at the domain root, affecting all domain-joined systems.
Securelist
2026-04-01
Operational disruption initiated
The GPO pushed ransom notes and altered system settings across the network.
X
2026-04-01
Data exfiltration observed
Sensitive data was exfiltrated from file servers and later published on the dark web.
Securelist
2026-09-21
Incident disclosed
Kaspersky's GERT published details of the incident, highlighting the attack method and implications.
Securelist

More articles in this cluster (4)

Following this threat?

Track Storm-0501, Apt29 and Cobalt Strike in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed