started · updated
PAYLOAD ransomware uses Group Policy to disrupt networks without encryption
Kaspersky’s Global Emergency Response Team (GERT) has identified a significant shift in ransomware tactics involving the PAYLOAD malware family. During an incident at a manufacturing company in the Middle East in April 2026, attackers bypassed traditional file encryption to cause operational disruption.
Instead of deploying standard encryptors, the threat actors gained domain administrator-equivalent privileges and weaponized Microsoft Active Directory Group Policy Objects (GPOs). They created a malicious GPO named ‘PAYLOAD’ linked at the domain root, which allowed them to control all domain-joined Windows workstations. The attack included changing desktop wallpapers and lock screens, displaying ransom notes, enforcing logon banners, and deactivating local administrator accounts.
A second GPO, named ‘win Firewall Off’, was used to disable Windows Firewall across the entire network. While the Windows endpoints remained unencrypted, the attackers exfiltrated sensitive data from file servers and subsequently published it on the dark web. The only traditional ransomware component identified was a PAYLOAD sample targeting ESXi on Linux servers. This ‘encryptionless extortion’ method focuses on immediate operational paralysis and data theft rather than cryptographic locking.
Entities
Active Directory · Fortinet · Kaspersky · Middle East · Payload
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 5 SOURCES] The attack included changing desktop wallpapers, lock screens, and enforcing a logon banner. cybernoz.com · cyberinsider.com · donanimgunlugu.com · www.technadu.com · securelist.com
- [● 2 SOURCES] A PAYLOAD ransomware sample targeting ESXi on Linux servers was identified during the incident. www.technadu.com · securelist.com
- [● 4 SOURCES] The attackers gained initial access via a compromised domain credential through a FortiGate SSL VPN. cybernoz.com · cyberinsider.com · www.technadu.com · securelist.com
- [● 6 SOURCES] The PAYLOAD ransomware attack targeted a manufacturing organization in the Middle East in April 2026. cybernoz.com · cyberinsider.com · donanimgunlugu.com · www.lahzanews.com · www.technadu.com · +1 more
- [● 3 SOURCES] Data was exfiltrated from file servers and subsequently published on the dark web. cyberinsider.com · www.technadu.com · securelist.com
- [● 6 SOURCES] Attackers used a malicious Group Policy Object (GPO) named ‘PAYLOAD’ to disrupt systems without encrypting files. cybernoz.com · cyberinsider.com · donanimgunlugu.com · www.lahzanews.com · www.technadu.com · +1 more
- [● 3 SOURCES] A second GPO named ‘win Firewall Off’ was used to disable Windows Firewall across the domain. cybernoz.com · cyberinsider.com · www.technadu.com
- [● 4 SOURCES] The attackers deactivated the local Administrator account on domain-joined systems. cybernoz.com · cyberinsider.com · www.technadu.com · securelist.com