GPO Manipulation refers to adversaries modifying Group Policy Objects within an Active Directory environment to deploy malicious configurations, startup scripts, or registry changes across domain-joined hosts.
GPO Manipulation is a mitre_attack tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed December 16, 2025; most recent activity December 16, 2025.
GPO Manipulation refers to adversaries modifying Group Policy Objects within an Active Directory environment to deploy malicious configurations, startup scripts, or registry changes across domain-joined hosts. This technique enables persistent, domain-wide control, facilitating stealthy lateral movement and defense evasion. It is significant because a single compromised domain controller can influence many endpoints, making it a powerful and risky method for attackers, including ransomware operators.
The Gentlemen ransomware operation has affected at least 17 countries across the Americas, Asia-Pacific, and the Middle East, targeting sectors such as manufacturing, healthcare, construction, and insurance. This…
GPO Manipulation refers to adversaries modifying Group Policy Objects within an Active Directory environment to deploy malicious configurations, startup scripts, or registry changes across domain-joined hosts.
The most recent intelligence report mentioning GPO Manipulation on ThreatCluster is dated December 16, 2025.
Across ThreatCluster reporting, GPO Manipulation most frequently co-occurs with Ransomware, Construction, Healthcare, Insurance, Manufacturing, among 12 tracked related entities.
The most significant recent cluster is “Gentlemen Ransomware Targets Global Industries Amid LLM Integration” (26 articles · Updated December 17, 2025). GPO Manipulation appears across 1 threat cluster in total, listed above with sources.
GPO Manipulation appears in 1 intelligence report mention across 1 deduplicated threat cluster, aggregated from 17,000+ monitored sources.