Opens in a new tab

PAYLOAD Ransomware Hijacks Active Directory GPO

Ransomware actors hijack AD Group Policy for domain-wide extortion without encryption

PAYLOAD ransomware has demonstrated how attackers can turn Active Directory Group Policy into a domain-wide extortion tool. In an incident investigated in April 2026, a malicious policy disrupted every domain-joined Windows workstation without deploying Windows ransomware or encrypting files.

Kaspersky’s Global Emergency Response Team reported the case on 21 September 2026. The victim was a manufacturing organisation in the Middle East, where attackers obtained privileges equivalent to a domain administrator and used trusted infrastructure to distribute their changes.

PAYLOAD ransomware attack compromised Group Policy

The attackers created a malicious Group Policy Object named PAYLOAD and linked it at the root of the victim’s Active Directory domain. This placement gave the policy an extensive scope because it applied to the computer and user objects beneath the domain root.

Through this single GPO, the attackers distributed ransom notes, replaced desktop wallpaper and lock screen images, and enforced a logon banner. They also disabled the local administrator account across every domain-joined Windows workstation, increasing the operational difficulty of recovering affected endpoints.

The Windows component of the PAYLOAD ransomware incident did not behave like conventional file-encrypting malware. Investigators confirmed that no files were encrypted on Windows machines, no malicious binaries remained on disk, no endpoint persistence had been installed and no malicious processes were running when the environment was analysed.

The only ransomware sample found during the investigation was a PAYLOAD sample targeting ESXi in the organisation’s server environment. The report does not identify specific Active Directory, Windows or ESXi versions, and it does not describe the GPO activity as the exploitation of a software vulnerability or CVE.

Data theft accompanied the disruption

Although Windows data was not encrypted, the incident was not limited to visual disruption. Investigators observed data exfiltration from file servers and several additional systems. The stolen information was subsequently published on the dark web.

This made PAYLOAD ransomware an encryptionless extortion incident on Windows. The attackers combined data theft with highly visible domain-wide changes, using the possibility of further disruption and public exposure as leverage rather than relying solely on cryptographic denial of access.

How the malicious PAYLOAD GPO worked

A Group Policy Object has two principal components. The Group Policy Container is stored in Active Directory, while the Group Policy Template is held in SYSVOL, the shared location used to distribute policy data to domain controllers and connected systems.

Administrators can link a GPO at the site, domain or organisational unit level. A policy linked to a limited organisational unit might affect only a particular department or group of computers. In this incident, the domain-root link gave the malicious PAYLOAD GPO the broadest practical reach within the affected domain.

Windows systems routinely retrieve and process legitimate Group Policy settings. Those policies can make security and configuration changes with elevated privileges, so endpoints treated the attacker’s instructions as authorised administration rather than an unknown executable attempting to run.

This trusted processing route helped the attackers avoid controls focused on suspicious files and processes. Kaspersky described Group Policy as a signed, allowlisted and SYSTEM-privileged distribution channel that many endpoint detection and response products are not designed to inspect in the same way as ordinary executable activity.

The attack therefore lived inside Active Directory rather than individual Windows installations. Cleaning or rebuilding an endpoint would not have removed the cause because the malicious GPO could be processed again when the machine reconnected to the domain or refreshed its policies.

Visible effects could follow a restart

The absence of a Windows ransomware binary also changed how the incident became visible. An organisation relying on malware detection could have seen no conventional ransomware alert before endpoints restarted and displayed the attacker’s wallpaper, lock screen or logon message.

The report does not disclose how the attackers initially entered the network or obtained domain administrator-equivalent privileges. However, once that level of control was achieved, no additional endpoint exploit was required to distribute the PAYLOAD ransomware effects across in-scope Windows systems.

A confirmed incident, not a theoretical technique

This was an investigated attack affecting a real manufacturing environment, not a proof of concept. Kaspersky confirmed the malicious domain-root GPO, widespread Windows policy changes, data exfiltration and subsequent publication of stolen information.

The available report does not establish the size of the affected organisation, the number of endpoints involved or whether the same actor has deployed PAYLOAD ransomware against other victims. It also does not identify a broader campaign or provide evidence that unconnected Active Directory environments are being automatically targeted.

The immediate exploitation status is therefore specific but significant. Attackers successfully weaponised legitimate Active Directory functionality after gaining powerful administrative access. This required control of the victim’s environment, rather than remote exploitation of an unpatched Group Policy product.

Why the PAYLOAD ransomware case matters

The incident shows that ransomware impact does not require a ransomware executable on every endpoint. Administrative infrastructure can itself provide the distribution, persistence and privilege needed to impose disruptive changes at scale.

It also demonstrates why a lack of encryption should not be interpreted as a failed attack. The victim still faced stolen data, public disclosure, disabled local administrator access and domain-wide interference with user interfaces and logon behaviour.

Actions for Active Directory defenders

Organisations using Active Directory should prioritise checks that relate directly to this attack path. Monitoring only endpoint files and processes is unlikely to identify a malicious GPO before its settings are applied.

  • Review newly created GPOs, unexpected policy edits and links added at the domain root.
  • Alert on changes to SYSVOL and the corresponding Group Policy Container in Active Directory.
  • Restrict and audit accounts able to create, edit or link GPOs, especially domain-level administrators.
  • Check policies that alter wallpaper, lock screens, logon banners or local administrator account settings.
  • During recovery, remove the malicious policy and verify Active Directory and SYSVOL integrity before reconnecting rebuilt endpoints.

Teams should also investigate unusual outbound transfers from file servers and other high-value systems. In this PAYLOAD ransomware case, data exfiltration was central to the extortion, even though Windows files were not encrypted.

Originally reported by securelist.com.

Share this bulletin

About the Author

Rob McBride Headshot - CyPro Partner and leading cyber security expert

Rob McBride

Partner

  • CISSP
  • ACA Chartered Accountant
  • MPhil
  • BSc
  • SOC 2
  • ISO 27001

Rob McBride

Rob is a Founding Partner at CyPro and a highly experienced CISO. Beginning his career with a successful tenure at Deloitte, Rob has since amassed a wealth of experience, notably serving as a cyber security advisor to the UK government and spearheading cloud security transformations for several global banks.

At CyPro, Rob leads the managed service business line, working extensively across multiple sectors including telecommunications, technology, higher education, travel, and retail. He is passionate about equipping small and medium-sized businesses (SMBs) with robust cyber security strategies to fuel their growth.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call