< Back to situations

Monitor this situation.

[SITUATION] · [ACTIVE] · [TECHNOLOGY]

2 clusters · 11 sources · 2 days · First seen · Last updated

PAYLOAD ransomware encryptionless extortion tactics

Overview

Kaspersky’s Global Emergency Response Team (GERT) has identified a new ransomware tactic involving the PAYLOAD malware family that focuses on “encryptionless extortion.” During an investigation into an April 2026 incident at a Middle Eastern manufacturing company, researchers found that attackers bypassed traditional file encryption to achieve operational paralysis and data theft.

By obtaining domain administrator-equivalent privileges—potentially through a FortiGate SSL VPN using compromised credentials—the threat actors weaponized Microsoft Active Directory Group Policy Objects (GPOs). They deployed a malicious GPO named ‘PAYLOAD’ to control all domain-joined Windows workstations, allowing them to change wallpapers, display ransom notes, and deactivate local administrator accounts. A second GPO, ‘win Firewall Off’, was used to disable Windows Firewall across the network.

While the attackers exfiltrated sensitive data from file servers for publication on the dark web, the primary method of disruption relied on network administration tools rather than cryptographic locking of individual files. The only traditional ransomware component identified was a PAYLOAD sample targeting ESXi on Linux servers.

Entities

Kaspersky · Fortinet · Payload · Cl0p · Middle East

Timeline

  1. 7 days ago

    [TECHNOLOGY] 3 sources
    Kaspersky identifies ransomware tactic using network administration

    Kaspersky researchers discovered a new ransomware tactic where attackers use Group Policy Objects to control networks and display ransom messages without encrypting files.

  2. 8 days ago

    [TECHNOLOGY] 8 sources
    PAYLOAD ransomware uses Group Policy to disrupt networks without encryption

    The PAYLOAD ransomware family has evolved to use Windows Group Policy to disrupt networks without encrypting files, instead hijacking system settings and deactivating security features to extort victims.

Sources

cnbcindonesia.com · cyberinsider.com · cybernoz.com · donanimgunlugu.com · itsection.com.br · jawapos.com · lahzanews.com · minutodaseguranca.blog.br · pemilu2024.harianjogja.com · securelist.com · technadu.com