PAYLOAD Ransomware Used Malicious Active Directory Policies to Disrupt a Manufacturing Firm

· Original article ↗

Summary

Kaspersky investigated a 2026 attack in which a compromised VPN account was used to deploy malicious Group Policy Objects across a manufacturing firm's domain. The attack disrupted Windows systems without encrypting their files, while data was exfiltrated.

Key points

  • The actor accessed the network through the FortiGate SSL VPN using a valid but compromised domain credential; the original source of the credential was not determined.
  • With domain-level GPO rights, the actor linked malicious PAYLOAD and “win Firewall Off” policies at the domain root, affecting domain-joined systems.
  • PAYLOAD changed wallpapers and lock screens, displayed ransom notes, distributed note files, and disabled local administrator accounts; the second GPO disabled Windows Firewall.
  • The policies were created on April 13, 2026, and took effect when endpoints rebooted the next day. No Windows files were encrypted, and investigators found no resident malware or endpoint persistence.
  • Data exfiltration from file servers and other systems was observed, and the stolen data was later published on the dark web. A PAYLOAD sample targeting ESXi on Linux servers was also found.
  • Kaspersky recommends auditing directory-service changes, monitoring SYSVOL for unexpected changes, and restricting privileged GPO creation and linking. Its guidance also covers removing the malicious policies and hardening VPN access.

Article Details

Victim Organization
An unnamed manufacturing organization in the Middle East
Incident Type
Compromised-account access through FortiGate SSL VPN, followed by malicious Active Directory Group Policy changes, data exfiltration and encryptionless extortion
Incident Date
2026-04-11
Operational Impact
Domain-root-linked GPOs disrupted domain-joined Windows workstations after reboot: ransom imagery and notes appeared, the local administrator account was disabled, and Windows Firewall was disabled on all profiles. Kaspersky confirmed no Windows file encryption or resident endpoint malware. Data exfiltration was observed from file servers and additional systems; the article says the data was later published on the dark web.
Ransom Or Extortion
Ransom notes, a logon banner and ransom imagery were deployed. The article describes extortion without confirmed Windows file encryption; it does not disclose a ransom amount.
Claim Status
confirmed

Indicators of compromise

TypeIndicatorContext
IPV4104[.]164[.]55[.]46IP address listed in the article's indicators of compromise.
IPV4104[.]28[.]162[.]228IP address listed in the article's indicators of compromise.
IPV4104[.]28[.]163[.]162IP address listed in the article's indicators of compromise.
IPV4146[.]70[.]117[.]239IP address listed in the article's indicators of compromise.
IPV4149[.]102[.]229[.]154IP address listed in the article's indicators of compromise.
IPV4192[.]42[.]116[.]12IP address listed in the article's indicators of compromise.
IPV4192[.]42[.]116[.]50IP address listed in the article's indicators of compromise.
IPV4192[.]42[.]116[.]52IP address listed in the article's indicators of compromise.
IPV4192[.]42[.]116[.]56IP address listed in the article's indicators of compromise.
IPV4192[.]42[.]116[.]97IP address listed in the article's indicators of compromise.
IPV437[.]19[.]210[.]12IP address listed in the article's indicators of compromise.
IPV464[.]190[.]76[.]14IP address listed in the article's indicators of compromise.
MD50108656a3e1ade6ca4f21b084f5e1208MD5 listed for killer.exe, a process-killer tool in the article's indicators of compromise.
MD5bea5e267f24d7da59f6821bffdbff293MD5 listed for kill.exe, a process-killer tool in the article's indicators of compromise.

MITRE ATT&CK

Malware

Vendors

Products

Tools

Industries

Related Articles