PAYLOAD ransomware has demonstrated how attackers can turn Active Directory Group Policy into a domain-wide extortion tool. In an incident investigated in April 2026, a malicious policy disrupted every domain-joined Windows workstation without deploying Windows ransomware or encrypting files.
Kaspersky’s Global Emergency Response Team reported the case on 21 September 2026. The victim was a manufacturing organisation in the Middle East, where attackers obtained privileges equivalent to a domain administrator and used trusted infrastructure to distribute their changes.
PAYLOAD ransomware attack compromised Group Policy
The attackers created a malicious Group Policy Object named PAYLOAD and linked it at the root of the victim’s Active Directory domain. This placement gave the policy an extensive scope because it applied to the computer and user objects beneath the domain root.
Through this single GPO, the attackers distributed ransom notes, replaced desktop wallpaper and lock screen images, and enforced a logon banner. They also disabled the local administrator account across every domain-joined Windows workstation, increasing the operational difficulty of recovering affected endpoints.
The Windows component of the PAYLOAD ransomware incident did not behave like conventional file-encrypting malware. Investigators confirmed that no files were encrypted on Windows machines, no malicious binaries remained on disk, no endpoint persistence had been installed and no malicious processes were running when the environment was analysed.
The only ransomware sample found during the investigation was a PAYLOAD sample targeting ESXi in the organisation’s server environment. The report does not identify specific Active Directory, Windows or ESXi versions, and it does not describe the GPO activity as the exploitation of a software vulnerability or CVE.
Data theft accompanied the disruption
Although Windows data was not encrypted, the incident was not limited to visual disruption. Investigators observed data exfiltration from file servers and several additional systems. The stolen information was subsequently published on the dark web.
This made PAYLOAD ransomware an encryptionless extortion incident on Windows. The attackers combined data theft with highly visible domain-wide changes, using the possibility of further disruption and public exposure as leverage rather than relying solely on cryptographic denial of access.
How the malicious PAYLOAD GPO worked
A Group Policy Object has two principal components. The Group Policy Container is stored in Active Directory, while the Group Policy Template is held in SYSVOL, the shared location used to distribute policy data to domain controllers and connected systems.
Administrators can link a GPO at the site, domain or organisational unit level. A policy linked to a limited organisational unit might affect only a particular department or group of computers. In this incident, the domain-root link gave the malicious PAYLOAD GPO the broadest practical reach within the affected domain.
Windows systems routinely retrieve and process legitimate Group Policy settings. Those policies can make security and configuration changes with elevated privileges, so endpoints treated the attacker’s instructions as authorised administration rather than an unknown executable attempting to run.
This trusted processing route helped the attackers avoid controls focused on suspicious files and processes. Kaspersky described Group Policy as a signed, allowlisted and SYSTEM-privileged distribution channel that many endpoint detection and response products are not designed to inspect in the same way as ordinary executable activity.
The attack therefore lived inside Active Directory rather than individual Windows installations. Cleaning or rebuilding an endpoint would not have removed the cause because the malicious GPO could be processed again when the machine reconnected to the domain or refreshed its policies.
Visible effects could follow a restart
The absence of a Windows ransomware binary also changed how the incident became visible. An organisation relying on malware detection could have seen no conventional ransomware alert before endpoints restarted and displayed the attacker’s wallpaper, lock screen or logon message.
The report does not disclose how the attackers initially entered the network or obtained domain administrator-equivalent privileges. However, once that level of control was achieved, no additional endpoint exploit was required to distribute the PAYLOAD ransomware effects across in-scope Windows systems.
A confirmed incident, not a theoretical technique
This was an investigated attack affecting a real manufacturing environment, not a proof of concept. Kaspersky confirmed the malicious domain-root GPO, widespread Windows policy changes, data exfiltration and subsequent publication of stolen information.
The available report does not establish the size of the affected organisation, the number of endpoints involved or whether the same actor has deployed PAYLOAD ransomware against other victims. It also does not identify a broader campaign or provide evidence that unconnected Active Directory environments are being automatically targeted.
The immediate exploitation status is therefore specific but significant. Attackers successfully weaponised legitimate Active Directory functionality after gaining powerful administrative access. This required control of the victim’s environment, rather than remote exploitation of an unpatched Group Policy product.
Why the PAYLOAD ransomware case matters
The incident shows that ransomware impact does not require a ransomware executable on every endpoint. Administrative infrastructure can itself provide the distribution, persistence and privilege needed to impose disruptive changes at scale.
It also demonstrates why a lack of encryption should not be interpreted as a failed attack. The victim still faced stolen data, public disclosure, disabled local administrator access and domain-wide interference with user interfaces and logon behaviour.
Actions for Active Directory defenders
Organisations using Active Directory should prioritise checks that relate directly to this attack path. Monitoring only endpoint files and processes is unlikely to identify a malicious GPO before its settings are applied.
- Review newly created GPOs, unexpected policy edits and links added at the domain root.
- Alert on changes to SYSVOL and the corresponding Group Policy Container in Active Directory.
- Restrict and audit accounts able to create, edit or link GPOs, especially domain-level administrators.
- Check policies that alter wallpaper, lock screens, logon banners or local administrator account settings.
- During recovery, remove the malicious policy and verify Active Directory and SYSVOL integrity before reconnecting rebuilt endpoints.
Teams should also investigate unusual outbound transfers from file servers and other high-value systems. In this PAYLOAD ransomware case, data exfiltration was central to the extortion, even though Windows files were not encrypted.
Originally reported by securelist.com.






