Ransomware & Extortion · Ransomware

PAYLOAD Used Active Directory to Extort a Whole Fleet

Kaspersky GERT said an attacker used Active Directory domain-admin access in April 2026 to deploy a malicious Group Policy Object named PAYLOAD at a manufacturing organization, affecting every domain-joined Windows workstation. The operation delivered ransom notes, lock-screen and wallpaper changes, a logon banner, and disabled local administrator accounts without dropping a Windows ransomware binary or encrypting files.

The mechanism was control-plane abuse: the attacker changed policy in the directory, and the next refresh pushed the same extortion message and settings to the whole fleet from the trusted Group Policy channel. Kaspersky also found a ransomware sample aimed at VMware ESXi on Linux servers, while data exfiltration from file servers and other systems was observed and later posted on the dark web.

For defenders, the lasting lesson is that a domain-admin compromise can become org-wide disruption even when endpoint tools never see a local ransomware process. If Active Directory and Group Policy are the trust center for a Windows estate, the exposure sits in that control plane as much as on any one workstation.

1 source · 15h ago

Timeline

Sources

Vendor digest: Microsoft

Vendor digest: VMware

Part of the PlainSec briefing for 2026-09-21

Every edition of this story: PAYLOAD Used Active Directory to Extort a Whole Fleet

More from today