PAYLOAD Ransomware Abuses Active Directory Group Policy to Disrupt Entire Windows Domain
PAYLOAD ransomware abused Active Directory Group Policy to disrupt a Windows domain without using file encryption.
A ransomware incident used Active Directory Group Policy Objects (GPOs) to disrupt a Windows domain without encrypting files or leaving malware on endpoints. Attackers gained access via compromised credentials on a FortiGate SSL VPN and used malicious GPOs to deploy ransom notes and disable firewalls. This approach bypassed traditional ransomware detection by abusing legitimate administrative tools.
75