Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [TECHNOLOGY]
2 clusters · 11 sources · 2 days · First seen · Last updated
PAYLOAD ransomware encryptionless extortion tactics
Overview
Kaspersky’s Global Emergency Response Team (GERT) has identified a new ransomware tactic involving the PAYLOAD malware family that focuses on “encryptionless extortion.” During an investigation into an April 2026 incident at a Middle Eastern manufacturing company, researchers found that attackers bypassed traditional file encryption to achieve operational paralysis and data theft.
By obtaining domain administrator-equivalent privileges—potentially through a FortiGate SSL VPN using compromised credentials—the threat actors weaponized Microsoft Active Directory Group Policy Objects (GPOs). They deployed a malicious GPO named ‘PAYLOAD’ to control all domain-joined Windows workstations, allowing them to change wallpapers, display ransom notes, and deactivate local administrator accounts. A second GPO, ‘win Firewall Off’, was used to disable Windows Firewall across the network.
While the attackers exfiltrated sensitive data from file servers for publication on the dark web, the primary method of disruption relied on network administration tools rather than cryptographic locking of individual files. The only traditional ransomware component identified was a PAYLOAD sample targeting ESXi on Linux servers.
Entities
Kaspersky · Fortinet · Payload · Cl0p · Middle East
Timeline
-
7 days ago
[TECHNOLOGY] 3 sourcesKaspersky identifies ransomware tactic using network administrationKaspersky researchers discovered a new ransomware tactic where attackers use Group Policy Objects to control networks and display ransom messages without encrypting files.
-
8 days ago
[TECHNOLOGY] 8 sourcesPAYLOAD ransomware uses Group Policy to disrupt networks without encryptionThe PAYLOAD ransomware family has evolved to use Windows Group Policy to disrupt networks without encrypting files, instead hijacking system settings and deactivating security features to extort victims.
Sources
cnbcindonesia.com · cyberinsider.com · cybernoz.com · donanimgunlugu.com · itsection.com.br · jawapos.com · lahzanews.com · minutodaseguranca.blog.br · pemilu2024.harianjogja.com · securelist.com · technadu.com