Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO

Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO
Kaspersky GERT investigated a 2026 incident where attackers hijacked Active Directory Group Policy to deploy PAYLOAD ransomware effects across a Middle East manufacturing organization without dropping a Windows encryptor. The activity included domain-root GPO abuse, SYSVOL staging, firewall disabling, data exfiltration, and publication of stolen data on the dark web. #PAYLOAD #FortiGate #ActiveDirectory #SYSVOL

Keypoints

  • The attacker gained domain admin-equivalent control of Active Directory and created a malicious domain-root GPO named PAYLOAD.
  • The PAYLOAD GPO delivered ransom notes, changed wallpaper and lock screen, enforced a logon banner, and disabled the local Administrator account.
  • No ransomware binary was dropped on Windows endpoints, no files were encrypted, and no malicious processes were found during analysis.
  • A second GPO named win Firewall Off disabled Windows Firewall across the domain to reduce host defenses.
  • Data exfiltration was observed from file servers and other systems, and the stolen data was later published on the dark web.
  • The attack relied on trusted Active Directory infrastructure and delayed policy application, allowing the payload to detonate after endpoint reboots.
  • Kaspersky recommended GPO auditing, SYSVOL integrity monitoring, privileged access hardening, and detection rules for suspicious GPO changes.

MITRE Techniques

  • [T1078 ] Valid Accounts – The attacker authenticated to the FortiGate SSL VPN using a compromised legitimate credential (‘initial access through a valid but compromised domain credential’).
  • [T1133 ] External Remote Services – FortiGate SSL VPN was used as the entry point into the environment (‘authenticate through the organization’s FortiGate SSL VPN’).
  • [T1078.002 ] Domain Accounts – The compromised account had domain-level rights to create and link GPOs (‘able to create and link a GPO at the domain root’).
  • [T1484.001 ] Group Policy Modification – Malicious PAYLOAD GPO was created and linked at the domain root to deliver impact (‘malicious GPO, PAYLOAD, created and linked at the domain root’).
  • [T1562.004 ] Disable or Modify System Firewall – The win Firewall Off GPO disabled Windows Firewall on all profiles (‘disabled Windows Firewall across the domain’).
  • [T1491.001 ] Internal Defacement – Wallpaper and lock screen were replaced with a ransom image (‘ransom wallpaper, logon banner, and notes appear’).
  • [T1531 ] Account Access Removal – The local Administrator account was disabled through GPO Security Settings (‘administrator account status Disabled’).
  • [T1005 ] Data from Local System – Data exfiltration was observed from file servers and additional systems (‘Data exfiltration was observed originating from the file servers’).
  • [T1685.005 ] Indicator Removal on Host: Clear Windows Event Logs – Public PAYLOAD samples can clear event logs to reduce forensic visibility (‘clears individual channels’).
  • [T1685 ] Indicator Removal on Host – PAYLOAD analysis describes security process/service termination and ETW suppression capabilities (‘targets security processes and services’, ‘patch ETW-related functions’).
  • [T1489 ] Service Stop – PAYLOAD samples may terminate services to interrupt protection and recovery (‘targets security processes and services’).
  • [T1490 ] Inhibit System Recovery – Public PAYLOAD sample analysis reports deletion of Volume Shadow Copies before encryption (‘deletion of Windows Volume Shadow Copies before encryption’).
  • [T1068 ] Exploitation for Privilege Escalation – BYOVD is described as a vulnerable-driver path to kernel-level control (‘introducing or abusing a legitimately signed but vulnerable kernel driver’).

Indicators of Compromise

  • [GPO names and GUIDs ] Malicious domain-root policies used in the incident – PAYLOAD {C897F2C7-C2AC-4E6F-BF48-58036FF29E79}, win Firewall Off {22099AD2-E062-4F56-B574-5099BBA4E7A6}
  • [File names ] SYSVOL-staged and dropped payload files – payload.jpg, hello.txt, README-payload.txt, and 2 more items
  • [MD5 hashes ] Hashes tied to process-killer tools mentioned in the report – 0108656A3E1ADE6CA4F21B084F5E1208, BEA5E267F24D7DA59F6821BFFDBFF293
  • [IP addresses ] Network indicators listed in the IOC section – 37.19.210[.]121, 46.70.117[.]239, and 10 more items
  • [Registry keys ] GPO-related and legal notice registry values changed by the attack – HKLM…PoliciesSystemlegalnoticecaption, HKLM…PoliciesSystemlegalnoticetext
  • [SYSVOL paths ] Files staged on the domain controller share – DC.THECOMPANY.localsysvolTHECOMPANY.localpayload.jpg, DC.THECOMPANY.localsysvolTHECOMPANY.localhello.txt
  • [Event IDs ] Audit artifacts associated with GPO activity – 5137, 5136, 4663, 4657, and 1102


Read more: https://securelist.com/tr/payload-ransomware-via-group-policy/121335/