PAYLOAD Used Active Directory to Extort a Whole Fleet
Kaspersky GERT said an attacker used Active Directory domain-admin access in April 2026 to deploy a malicious Group Policy Object named PAYLOAD at a manufacturing organization, affecting every domain-joined Windows workstation. The operation delivered ransom notes, lock-screen and wallpaper changes, a logon banner, and disabled local administrator accounts without dropping a Windows ransomware binary or encrypting files.
The mechanism was control-plane abuse: the attacker changed policy in the directory, and the next refresh pushed the same extortion message and settings to the whole fleet from the trusted Group Policy channel. Kaspersky also found a ransomware sample aimed at VMware ESXi on Linux servers, while data exfiltration from file servers and other systems was observed and later posted on the dark web.
For defenders, the lasting lesson is that a domain-admin compromise can become org-wide disruption even when endpoint tools never see a local ransomware process. If Active Directory and Group Policy are the trust center for a Windows estate, the exposure sits in that control plane as much as on any one workstation.
PAYLOAD ransomware attacks through Active Directory GPO
Kaspersky GERT experts dive into the technical incident analysis of PAYLOAD ransomware: an encryptionless, binary-less operation that abused Active Directory mechanisms for managing Group Policy Objects.