Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO

Imported from official source

Cybersecurity Classified by Officially

Kaspersky GERT experts dive into the technical incident analysis of PAYLOAD ransomware: an encryptionless, binary-less operation that abused Active Directory mechanisms for managing Group Policy Objects.

This is an extract. The publication continues at the source.

Read the original at the source: https://securelist.com/tr/payload-ransomware-via-group-policy/121335/

Officially imported this from Kaspersky Securelist’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Kaspersky Securelist — imported from official source
Official source
https://securelist.com/feed/ RSS
Imported
September 21, 2026 11:00
Versions
1 recorded
Identity
https://kasperskycontenthub.com/securelist/tr/auto-draft/121335/

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.