Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO

Kaspersky Securelist Version 1 original current

Imported from official source

Kaspersky GERT experts dive into the technical incident analysis of PAYLOAD ransomware: an encryptionless, binary-less operation that abused Active Directory mechanisms for managing Group Policy Objects.

This version

Version
1 of 1
Recorded
September 21, 2026 11:00
Change
Initial
Content hash
43f6442d68c727ac6fdb3e143d2a9389
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.