PAYLOAD ransomware weaponizes Active Directory GPO
Kaspersky researchers detail a 2026 attack where threat actors used a malicious Group Policy Object named PAYLOAD to disrupt a manufacturing firm without

A manufacturing organization in the Middle East was compromised in April 2026 using a malicious Group Policy Object. Kaspersky's Global Emergency Response Team (GERT) found the threat actor had domain admin-level control and used a single GPO named PAYLOAD to deliver ransom notes, hijack desktops, and disable local administrator accounts across all Windows workstations.
The attack did not involve dropping a ransomware binary or encrypting data on Windows machines. The only ransomware sample found targeted ESXi on Linux servers. Data exfiltration from file servers was also observed and later published on the dark web. This case exemplifies two trends: the living-off-the-land abuse of trusted Active Directory infrastructure and the rise of encryptionless extortion.
Attack chain and GPO details
The actor gained initial access via a compromised valid account on the organization's FortiGate SSL VPN. Insufficient logging obscured how the credentials were obtained, with possibilities including password spraying, phishing, or purchased access. Once inside, the account held privileges to create and link a GPO at the domain root.
Instead of deploying an encryptor, the attacker configured two malicious GPOs linked at the domain root. The primary PAYLOAD GPO executed several disruptive actions through legitimate Group Policy mechanisms. A second GPO named "win Firewall Off" disabled Windows Firewall across all domain endpoints.
Forensic timeline and delayed impact
A critical forensic detail was a one-day delay between GPO creation and visible impact. The policy was written to SYSVOL on 13 April but only applied when endpoints rebooted on 14 April. This delay can provide attackers a quiet window for further staging and complicates incident timeline reconstruction for defenders.
Kaspersky's analysis confirmed no malicious binaries were resident on disk, no endpoint persistence was established, and no malicious processes were running at the time of investigation. The entire attack lived inside Active Directory.
Defensive implications and detection
The defensive implication is stark. An organization relying on detecting ransomware executables would see nothing until the first endpoint rebooted and displayed the ransom wallpaper. GPOs are a signed, allowlisted, SYSTEM-privileged distribution channel that most endpoint detection tools are not designed to inspect.
Kaspersky states, "By delivering impact through GPO rather than through malware, the actor sidestepped the entire file- and process-based detection stack." The firm advises organizations to monitor for suspicious GPO creation and linking events, especially at the domain root, and to ensure comprehensive directory service auditing is enabled.
Public threat intelligence has repeatedly documented GPO abuse. Microsoft observed Ryuk operators using the technique, while LockBit and BlackCat/ALPHV affiliates have modified SYSVOL files to support ransomware execution.





