PAYLOAD Extortion Skips Encryption, Exploits GPO
The PAYLOAD extortion operators recently targeted a Middle Eastern manufacturing enterprise without executing a single encryptor payload on any Windows machine. After successfully acquiring domain administrator privileges, the malicious actors weaponized Active Directory Group Policy Objects (GPOs) to distribute ransom demands across enterprise workstations. They systematically replaced desktop wallpapers and lock screens, maliciously disabled local administrator accounts, and deactivated the Windows Firewall. Tragically, the data exfiltrated from the compromised servers subsequently surfaced on the dark web.
The Kaspersky Global Emergency Response Team (GERT) comprehensively detailed this April intrusion on September 21. Within their exhaustive analysis, the researchers illuminate a highly unconventional extortion paradigm. Specifically, the fundamental Windows management infrastructure itself—rather than specialized malware—served as the primary offensive weapon.
Infiltration and Malicious GPO Deployment
The initial network penetration commenced on April 11. The adversary breached the internal perimeter via a FortiGate SSL VPN connection, leveraging a valid yet severely compromised domain account. Unfortunately, the VPN logs lacked sufficient granularity, preventing the researchers from definitively determining the precise credential harvesting methodology. Phishing, credential stuffing, reusing previously breached passwords, or purchasing access from a specialized Initial Access Broker remain highly plausible scenarios, though unconfirmed.
By April 13, the intruder possessed the requisite authorization to forge GPOs and bind them directly to the domain root. Such elevated capabilities correspond directly to domain administrator rights or equivalent delegated access. The attacker ominously named the malicious object “PAYLOAD”. Through this weaponized policy, the adversary orchestrated the display of ransom demands, manipulated desktop and lock screen backgrounds, injected intimidating logon banners, and completely disabled local administrator accounts. Concurrently, a secondary GPO, deceptively titled “win Firewall Off,” systematically dismantled the Windows Firewall across domain, private, and public network profiles. For a deeper technical dive, you can review the full report on how they deployed the PAYLOAD ransomware via group policy.
Leveraging SYSVOL for File Distribution
Fascinatingly, the cybercriminals did not even require a custom loader for file distribution. They simply deposited the payload.jpg and hello.txt files directly into SYSVOL, the standard, legitimate repository for group policy data. Consequently, the group policy engine automatically propagated the ransom demand file to user desktops and the root directories of C and D drives. Furthermore, malicious registry modifications forced Windows to display the extortionist’s text during the login sequence. Because the entire malicious logic resided exclusively within the Active Directory configuration, launching extraneous executable files on individual Windows endpoints proved entirely unnecessary.
The implementation of a deliberate delay proved particularly insidious. The attackers established the malicious policies on April 13, allowing the computers to silently receive and cache the detrimental settings without immediate consequence. This toxic configuration only activated on April 14, following routine workstation reboots. Upon restarting, users were confronted with aggressive ransom demands, altered wallpapers, and intimidating banners, severely disrupting the enterprise’s operations. For nearly 24 hours, the malicious configuration lay dormant, patiently waiting within standard Windows mechanisms.
Data Exfiltration and Absent Encryptors
Simultaneously, the attackers relentlessly exfiltrated sensitive information from the file servers and various other critical systems. GERT confirms that the cybercriminals subsequently published this stolen data on dark web leak sites. However, during meticulous forensic analysis, the specialists discovered absolutely no encrypted files, ransomware binaries, active malicious processes, or isolated persistence mechanisms on the affected Windows computers. The researchers did identify a PAYLOAD variant engineered for VMware ESXi residing on the enterprise’s Linux servers; however, they found no evidence confirming its deployment for encryption during this specific incident.
The PAYLOAD encryptor undeniably exists and actively targets both Windows and VMware ESXi environments. Independent research explicitly links this malware family to robust encryption routines based on ChaCha20 and Curve25519, with the group’s malicious activity traced back to at least February 2026. Therefore, the glaring absence of encryption in the April incident does not suggest a lack of capability. GERT currently assesses two highly probable scenarios with moderate confidence: the perpetrators either consciously restricted their operation to data theft and operational disruption, or they simply ran out of time before initiating the subsequent encryption phase.
The Grave Threat of Weaponized Group Policies
The malicious utilization of GPOs is not exclusive to the PAYLOAD operators. In March, Microsoft documented a separate, sophisticated attack where cybercriminals initially attempted to disable Defender security mechanisms via group policy, intending to utilize the exact same channel to distribute their encryptor later. Fortunately, in that instance, defensive measures successfully intercepted the propagation of the malicious policies across hundreds of devices.
The catastrophic danger of weaponized GPOs lies in their terrifying scalability. A single malicious policy, bound to the domain root, possesses the capability to alter the configuration of countless computers precisely like a legitimate administrative directive. Consequently, merely sanitizing individual workstations fundamentally fails to resolve the underlying crisis. As long as the malicious object persists within Active Directory, the detrimental settings will inevitably reapply during the next routine policy update cycle.
To proactively detect such sophisticated attacks, security specialists strongly advise rigorously monitoring the creation and modification of GPOs. Administrators must meticulously track Windows event IDs 5136, 5137, and 5141, relentlessly safeguard SYSVOL integrity, and strictly limit the privileges required to create and link policies. For VPNs and all external access points, implementing robust, phishing-resistant multi-factor authentication is absolutely essential. In the event of a confirmed compromise, incident responders must immediately eradicate the malicious policies from the domain controllers and revoke all compromised privileged credentials before attempting to restore any individual endpoint devices.
Ultimately, the PAYLOAD incident powerfully illustrates why the absence of encrypted files can no longer be interpreted as a positive indicator. Having achieved domain administrator control, an attacker can effortlessly steal data, dismantle defenses, and cripple an entire organization using nothing but standard, built-in Windows mechanisms. In this evolving threat landscape, the actual encryptor merely represents one of many possible concluding steps.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.