A ransomware operation, identified as PAYLOAD, showcases how attackers can leverage Microsoft Active Directory Group Policy Objects (GPOs) to disrupt an entire Windows domain without deploying endpoint ransomware or encrypting files. Kaspersky’s Global Emergency Response Team investigated the April 2026 incident at a Middle Eastern manufacturing organization, where attackers gained domain admin-equivalent privileges and created a malicious GPO named “PAYLOAD.” This policy was linked at the Active Directory domain root, affecting every in-scope domain-joined user and workstation. PAYLOAD Ransomware Hijacks Active Directory Group Policy The PAYLOAD GPO copied ransom notes to desktops and local drive roots, replacing desktop wallpaper and lock-screen images with ransom messages, configuring a logon banner, and disabling the built-in local Administrator account.
Initial access occurred on April 11 through the organization’s FortiGate SSL VPN using a valid compromised domain credential. Ioc Type Indicator Description Malicious GPO {C897F2C7-C2AC-4E6F-BF48-58036FF29E79} ransomware GPO linked at the Active Directory domain root Malicious GPO {22099AD2-E062-4F56-B574-5099BBA4E7A6} Win Firewall Off GPO used to disable Windows Firewall SYSVOL File payload.jpg ransomware wallpaper and lock-screen image distributed through Group Policy SYSVOL File hello.txt source ransom note stored in SYSVOL Dropped File README-payload.txt read-only ransom note copied to desktops and C:\ / D:\ drive roots File Hash (MD5) 0108656A3E1ADE6CA4F21B084F5E1208 killer.exe process-killing tool File Hash (MD5) BEA5E267F24D7DA59F6821BFFDBFF293 kill.exe process-killing tool Registry Value HKLM\...\Policies\System\legalnoticecaption = Welcome to Payload!











