PAYLOAD Ransomware Attacks Through Active Directory GPO
8 Articles
8 Articles
Kaspersky Uncovers Stealthy 'Payload' Ransomware Campaign
Islamabad (GNP): Kaspersky’s Global Emergency Response Team (GERT) has released a new report examining a sophisticated tactic used by the Payload ransomware family. Identified during an incident response at a manufacturing company in the Middle East, the attack marks a notable shift in cybercriminal strategy — attackers gained full control of the company’s network and […]
Kaspersky announced that Payload ransomware, detected at a manufacturing company, takes over devices without encrypting files. The attackers distributed ransom notes with administrator credentials and malicious GPOs, and published the data on the dark web; experts recommend monitoring the GPOs.
PAYLOAD Ransomware Abuses Active Directory Group Policy to Disrupt Entire Windows Domain
A ransomware incident in which attackers used Active Directory Group Policy to disrupt operations without deploying a Windows encryptor or leaving malware running on endpoints. In April 2026, the attackers accessed a FortiGate SSL VPN using compromised domain credentials, then gained domain-admin-equivalent rights. PAYLOAD Ransomware On April 13, Kaspersky’s Global Emergency Response Team (GERT) created
PAYLOAD Ransomware Hijacks Active Directory GPO to Disrupt Entire Windows Domain Without Encryption
A PAYLOAD ransomware attack used Active Directory Group Policy Objects to disrupt an entire Windows domain without encrypting files or deploying ransomware binaries. The operation targeted a manufacturing organization in the Middle East. It relied on domain-level control, stolen credentials, and malicious GPOs to display ransom demands, disable defenses, and lock down administrator access. In […]
New Kaspersky report points to growing trend of "extortion without encryption" Kaspersky's Global Emergency Response Team (GERT) has published a new report analyzing sophisticated new tactics within the Payload ransomware family. The attack was discovered during a security incident response at a manufacturing company in the Middle East and indicates [...]
Coverage Details
Bias Distribution
- There is no tracked Bias information for the sources covering this story.
Factuality
To view factuality data please Upgrade to Premium








