A ransomware operation tracked as PAYLOAD used Active Directory Group Policy Objects to disrupt an entire Windows domain without encrypting files or installing a traditional ransomware binary on endpoints.
The incident targeted a manufacturing organization in the Middle East. Attackers reportedly entered through a FortiGate SSL VPN in April using a valid but compromised domain account. The original source of the credentials remains unknown.
Trusted administration became the payload
After obtaining sufficient privileges, the attackers created a Group Policy Object named PAYLOAD and linked it to the root of the Active Directory domain. They also created a second policy called win Firewall Off.
The policies used normal Windows administration mechanisms to copy ransom notes from SYSVOL, replace desktop wallpapers and lock screens, display a logon banner, deactivate local Administrator accounts and disable Windows Firewall across domain, private and public profiles.
The attackers staged files in SYSVOL on April 13. As machines rebooted or refreshed policy the following day, the malicious configuration spread across the environment.
Kaspersky found no encrypted files, endpoint ransomware binary, suspicious long-running process or conventional persistence such as a service, scheduled task, Run key or WMI subscription. The linked GPO on the domain controller was the persistence and deployment mechanism.
Encryptionless extortion
Researchers also observed data theft before the visible disruption. The stolen information was later published on a leak site, showing an extortion model built around exfiltration and operational impact rather than file encryption.
This approach can evade controls that focus mainly on rapid file changes or known ransomware executables. It also turns an allowlisted enterprise-management system into a domain-wide attack channel.
What defenders should monitor
- Alert on Windows Event IDs 5137, 5136 and 5141 for GPO creation, modification and deletion.
- Monitor unexpected changes to the
gPLinkattribute at the domain root. - Track new or modified files in SYSVOL.
- Separate permission to create a GPO from permission to link one.
- Require phishing-resistant MFA for remote access and privileged administration.
- If compromised, remove malicious policies at the domain controller before cleaning endpoints, then rotate credentials and restore settings with known-good policies.
Sources
- Cyber Security News: PAYLOAD Ransomware Hijacks Active Directory GPO
- Kaspersky Securelist: PAYLOAD ransomware via Group Policy
