Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO
Kaspersky details PAYLOAD ransomware operators abusing Active Directory GPOs for encryptionless extortion at a Middle East manufacturer, exfiltrating data published on the dark web.
In April 2026, Kaspersky's GERT responded to a ransomware incident at a Middle East manufacturing organization where attackers with domain admin-equivalent access created a malicious GPO named PAYLOAD linked at the domain root. The GPO delivered ransom notes, hijacked wallpaper and lock screens, enforced a logon banner, and disabled the local administrator account across all domain-joined Windows machines without deploying an encryptor. Initial access came via a compromised FortiGate SSL VPN credential; data was exfiltrated and published on the dark web, and the only ransomware sample found targeted ESXi servers.