< Back to all clusters
[TECHNOLOGY] · Türkiye, United States · 8 sources

started · updated

PAYLOAD ransomware uses Group Policy to disrupt networks without encryption

Kaspersky’s Global Emergency Response Team (GERT) has identified a significant shift in ransomware tactics involving the PAYLOAD malware family. During an incident at a manufacturing company in the Middle East in April 2026, attackers bypassed traditional file encryption to cause operational disruption.

Instead of deploying standard encryptors, the threat actors gained domain administrator-equivalent privileges and weaponized Microsoft Active Directory Group Policy Objects (GPOs). They created a malicious GPO named ‘PAYLOAD’ linked at the domain root, which allowed them to control all domain-joined Windows workstations. The attack included changing desktop wallpapers and lock screens, displaying ransom notes, enforcing logon banners, and deactivating local administrator accounts.

A second GPO, named ‘win Firewall Off’, was used to disable Windows Firewall across the entire network. While the Windows endpoints remained unencrypted, the attackers exfiltrated sensitive data from file servers and subsequently published it on the dark web. The only traditional ransomware component identified was a PAYLOAD sample targeting ESXi on Linux servers. This ‘encryptionless extortion’ method focuses on immediate operational paralysis and data theft rather than cryptographic locking.

Entities

Active Directory · Fortinet · Kaspersky · Middle East · Payload

Claims

What the coverage asserts, and how many sources carry each claim.