PAYLOAD ransomware hijacks Active Directory GPOs to disrupt Middle East manufacturer's Windows domain without encryption
Kaspersky details an April 2026 PAYLOAD operation that entered a Middle East manufacturer via a compromised FortiGate SSL VPN account and used domain-root GPOs ('PAYLOAD' and 'win Firewall Off') to push ransom notes, hijack screens, and disable firewalls…
In April 2026, Kaspersky's GERT responded to a ransomware incident at a Middle East manufacturing organization. Initial access came via a valid compromised domain account on a FortiGate SSL VPN; the source of the credential theft is unconfirmed. With domain admin-equivalent privileges, the attackers created a malicious Group Policy Object named 'PAYLOAD' linked at the AD domain root, which delivered ransom notes, hijacked wallpaper and lock screens, enforced a 'Welcome to Payload!' logon banner, and disabled the local Administrator account on all domain-joined Windows machines. A second GPO, 'win Firewall Off', disabled Windows Firewall across domain, private, and public profiles. No files were encrypted and no binaries were deployed to endpoints; persistence came from the GPO link itself, with payload.jpg and hello.txt staged in SYSVOL. Data exfiltrated before the disruption was later published on a dark-web leak site — an encryptionless extortion model — and the only ransomware sample recovered targeted ESXi servers. Because GPO abuse runs through a trusted, SYSTEM-privileged Windows management channel, it bypasses file- and process-based EDR detection; Kaspersky recommends monitoring Event IDs 5136/5137/5141 and unexpected gPLink changes at the domain root. All three reports agree on the core facts; only the Kaspersky-sourced coverage specifies the victim sector, incident date, and GPO names, and GBHackers frames the VPN access as the route to domain-admin rights rather than the attackers already holding domain admin-equivalent access.
- Incident occurred in April 2026 at a Middle East manufacturing organization; Kaspersky's GERT responded
- Initial access via a valid compromised domain account on a FortiGate SSL VPN; the credential theft source is unconfirmed
- Malicious GPO 'PAYLOAD' linked at the AD domain root delivered ransom notes, hijacked wallpaper and lock screens, enforced a 'Welcome to Payload!' logon banner, and disabled the local Administrator account on all domain-joined Windows…
- A second GPO, 'win Firewall Off', disabled Windows Firewall across domain, private, and public profiles
- No files were encrypted and no endpoint binaries were deployed; persistence came from the GPO link itself, with payload.jpg and hello.txt staged in SYSVOL
- Exfiltrated data was published on a dark-web leak site, consistent with an encryptionless extortion model
- The only ransomware sample recovered in the investigation targeted ESXi servers
- GPO abuse is a trusted, SYSTEM-privileged Windows management channel that bypasses file- and process-based EDR detection
Coverage timelineoldest first · each row is one article
- · 5d agoGroup Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO
Kaspersky Securelist· 72
Kaspersky details PAYLOAD ransomware operators abusing Active Directory GPOs for encryptionless extortion at a Middle East manufacturer, exfiltrating data published on the dark web.
- · 5d agoPAYLOAD Ransomware Abuses Active Directory Group Policy to Disrupt Entire Windows Domain
GBHackers· 75
PAYLOAD ransomware abused Active Directory Group Policy to disrupt a Windows domain without using file encryption.
- · 5d ago