Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO

Executive Summary

Kaspersky GERT experts dissect PAYLOAD ransomware, an encryption‑less, binary‑less threat that hijacks Active Directory Group Policy Objects (GPOs) to propagate and execute malicious payloads. The analysis details how PAYLOAD leverages AD mechanisms for lateral movement and persistence, bypassing traditional security controls and highlighting the need for hardened GPO management.


Intelligence Metadata - Source Publisher: Securelist - Published Date: 2026-09-21T10:00:40+00:00 - Category: malware

Original Description: Kaspersky GERT experts dive into the technical incident analysis of PAYLOAD ransomware: an encryptionless, binary-less operation that abused Active Directory mechanisms for managing Group Policy Objects.

"Every person, all the events of your life are there because you have drawn them there. What you choose to do with them is up to you."

— Richard Bach
Source: Securelist