Payload Ransomware Abuses Group Policy to Disrupt Windows Domains
Key Takeaways A PAYLOAD ransomware variant leveraged Active Directory Group Policy Objects (GPOs) to compromise a manufacturing organization’s entire Windows domain. The attack caused...
Key Takeaways
- A PAYLOAD ransomware variant leveraged Active Directory Group Policy Objects (GPOs) to compromise a manufacturing organization’s entire Windows domain.
- The attack caused widespread disruption, displaying ransom demands and disabling defenses, but notably did not encrypt files or deploy traditional ransomware binaries on endpoints.
- Initial access was gained in April 2026 through a compromised FortiGate SSL VPN account, leading to domain-level control.
- The incident underscores a critical gap in ransomware defenses that primarily focus on file encryption, highlighting the need for robust Active Directory monitoring.
A sophisticated PAYLOAD ransomware operation recently paralyzed a Windows domain within a Middle Eastern manufacturing firm by exploiting Active Directory Group Policy Objects. This attack diverged significantly from typical ransomware methodologies, achieving widespread disruption and displaying ransom demands without encrypting a single file or deploying conventional ransomware executables on victim systems.
Table Of Content
The attackers established complete domain-level control using stolen credentials and then deployed malicious GPOs to broadcast ransom messages, dismantle security protocols, and block administrative access across the network.
The breach originated in April 2026 when threat actors reportedly accessed the organization’s FortiGate SSL VPN. This initial entry point utilized a legitimate, albeit compromised, domain account. While the precise method of credential theft remains unconfirmed, researchers speculate potential avenues included phishing, password spraying, credential stuffing, or the acquisition of credentials from an initial access broker.
Once elevated privileges were secured, the attackers created a malicious Group Policy Object, aptly named PAYLOAD, and linked it directly to the root of the Active Directory domain. This strategic placement ensured that the malicious policy would propagate to virtually every domain-joined device, transforming a powerful administrative tool into an instrument of enterprise-wide sabotage.
PAYLOAD Ransomware’s Unique Approach
The PAYLOAD GPO did not function as a traditional ransomware executable. Instead, it ingeniously manipulated trusted Windows policy mechanisms. It copied ransom notes from the SYSVOL share, replaced desktop wallpapers and lock screens with a ransom image, configured a logon banner displaying “Welcome to Payload!”, and deactivated the local Administrator account on affected machines.
In parallel, the attackers established a second GPO, named “win Firewall Off,” which systematically disabled the Windows Firewall across all domain, private, and public profiles throughout the network.
What made this particular attack exceptionally insidious was its minimal footprint on individual endpoints. Kaspersky’s analysis revealed no encrypted files, no malicious binaries residing on compromised Windows machines, no suspicious processes actively running, and no conventional endpoint persistence mechanisms such as scheduled tasks, services, Run keys, or WMI subscriptions.
Instead, the malicious GPO link on the domain controller itself served as the primary persistence method. On April 13, the attackers staged “payload.jpg” and “hello.txt” within the organization’s SYSVOL share. While endpoint systems cached the policy promptly, its full impact was deferred because many computer-level settings only took effect upon system reboot or policy refresh.
Consequently, on April 14, as endpoints began to reboot, ransom wallpapers, lock-screen images, login messages, and ransom-note files started appearing across the network, signaling the widespread disruption.
Prior to the visible network disruption, Kaspersky also detected data exfiltration from file servers and other systems. This stolen data was subsequently published on a dark-web leak site, confirming that the operation adhered to an encryptionless extortion model. Rather than relying on file encryption for leverage, the attackers combined data theft with operational disruption and the implicit threat of further escalation to coerce the victim.
Kaspersky said the incident highlights a growing vulnerability for organizations whose ransomware defenses are narrowly focused on detecting suspicious executables and encryption activity. GPOs are inherently trusted, often allowlisted, and high-privilege administrative tools. This inherent trust allows malicious policy changes to bypass security products primarily designed to inspect files, scripts, and processes.
What You Should Do
- Monitor Active Directory Changes: Implement robust monitoring for Active Directory modifications, specifically tracking Event IDs 5137 (GPO creation), 5136 (directory-object modifications), and 5141 (deletions).
- Alert on Unusual GPO Activity: Configure alerts for unexpected changes to the
gPLinkattribute at the domain root, the presence of unusual files in SYSVOL, and GPO modifications initiated by nonstandard administrative accounts. - Immediate Remediation: In the event of compromise, immediately remove malicious GPOs from domain controllers before attempting to clean endpoints.
- Credential Management: Rotate all compromised credentials and conduct a thorough review of privileged group memberships.
- Restore Settings: Revert firewall and administrator settings to their secure defaults through clean, trusted policies.
- Enforce MFA: Mandate phishing-resistant Multi-Factor Authentication (MFA) for all VPN access points.
- Strengthen GPO Controls: Monitor SYSVOL integrity rigorously and consider separating GPO creation rights from GPO linking rights to mitigate the risk of a domain-wide policy takeover.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.