< Back to all clusters
[TECHNOLOGY] · 3 sources

started · updated

Kaspersky identifies ransomware tactic using network administration

Kaspersky has identified a new ransomware attack method that avoids traditional file encryption. During an investigation into a security incident at a manufacturing company in the Middle East in April 2026, Kaspersky’s Global Emergency Response Team (GERT) discovered that attackers exploited network administration systems to gain widespread control.

By obtaining domain administrator privileges within the company’s Active Directory environment, the attackers created a malicious Group Policy Object (GPO) named ‘PAYLOAD’. This allowed them to simultaneously modify configurations across all connected Windows computers. The GPO was used to display ransom messages, change wallpapers and lock screens, show login notifications, and disable local administrator accounts, all without requiring a ransomware file to run on individual devices.

The initial breach occurred via a FortiGate SSL VPN using compromised valid domain credentials. While the exact method of credential theft remains unconfirmed, researchers suggest possibilities such as password spraying, credential stuffing, phishing, or purchasing access from an initial access broker.

Entities

Cl0p · Kaspersky · ShinyHunters