Incident
Published 2026-09-21
Verified 2026-09-21

Kaspersky GERT: PAYLOAD ransomware disrupts Windows domain via AD GPO — no encryption

Kaspersky Global Emergency Response Team (Securelist; published 21 September 2026) details an April 2026 incident at a Middle East manufacturing organisation where operators gained domain-admin-equivalent Active Directory control and linked a malicious Group Policy Object named PAYLOAD at the domain root — delivering enterprise-wide disruption without encrypting files or dropping a ransomware binary on endpoints. Initial access: compromised valid domain account authenticating to FortiGate SSL VPN (credential source unconfirmed — phishing, spraying/stuffing, or IAB considered). Impact via legitimate GPO client-side extensions: SYSVOL hello.txt staged as read-only README-payload.txt on desktops and C:\/D:\ roots; legal notice caption/text set to “Welcome to Payload!” plus ransom note; payload.jpg as lock-screen and wallpaper; administrator rights revoked via Security Settings CSE; a second domain-root GPO (“win Firewall Off”) disabled Windows Firewall across profiles. GPO written/cached 13 April with visible mass impact 14 April (typical GPO apply delay). Live hosts showed no encryptor processes, no .payload extensions, and no endpoint persistence — the persistence was the GPO link on the DC. Defensive focus: DS Access / gPLink change auditing, SYSVOL integrity (unexpected images/notes/registry.pol/GptTmpl.inf), and endpoint Group Policy Operational telemetry. Family-level PAYLOAD samples separately support log clearing, security-process kill, and VSS deletion — not confirmed executed in this GPO-only case. Amplify: Cyber Security News 21 September 2026. No CVE.

Product
Windows Active Directory / Group Policy (domain-joined estate); FortiGate SSL VPN (initial access path)
Versions
n/a (living-off-the-land AD GPO abuse; FortiGate SSL VPN with compromised valid account)
Exploited in Australia?
unknown
Patch to
Hunt domain-root gPLink / GPO creates by non-standard accounts; FIM SYSVOL for unexpected payload.jpg / hello.txt / README-payload.txt and GptTmpl.inf / registry.pol changes; alert on mass legal-notice / wallpaper / lock-screen / firewall-off policy pushes; tighten FortiGate SSL VPN MFA and credential hygiene; remediate by unlinking/removing malicious GPOs from DCs first, then credential reset and AD hardening per Kaspersky phases.

Primary: Kaspersky Securelist — PAYLOAD ransomware via Active Directory GPO (21 Sep 2026) · Vendor: Kaspersky GERT / Securelist primary IR write-up · Cyber Security News — PAYLOAD AD GPO amplify (21 Sep 2026)

breaches identity network