PAYLOAD Ransomware Hijacks Active Directory GPO to Disrupt Entire Windows Domain Without Encryption
PAYLOAD ransomware crew hijacked Active Directory GPOs to disrupt a Middle East manufacturer's entire Windows domain without encrypting files.
Kaspersky detailed an April 2026 PAYLOAD operation against a Middle East manufacturing firm that entered through a FortiGate SSL VPN using a compromised domain account. Attackers linked a malicious GPO named PAYLOAD to the AD domain root to push ransom notes, wallpapers, a 'Welcome to Payload!' logon banner, and disable the local Administrator account, while a second GPO ('win Firewall Off') disabled Windows Firewall across all profiles. No files were encrypted and no binaries were deployed; persistence came from the GPO link itself, with payload.jpg and hello.txt staged in SYSVOL. Data exfiltrated before the disruption was later published on a dark-web leak site, an encryptionless extortion model.