PAYLOAD Ransomware Used Malicious Active Directory Policies to Disrupt a Manufacturing Firm

Summary
Kaspersky investigated a 2026 attack in which a compromised VPN account was used to deploy malicious Group Policy Objects across a manufacturing firm's domain. The attack disrupted Windows systems without encrypting their files, while data was exfiltrated.
Key points
- The actor accessed the network through the FortiGate SSL VPN using a valid but compromised domain credential; the original source of the credential was not determined.
- With domain-level GPO rights, the actor linked malicious PAYLOAD and “win Firewall Off” policies at the domain root, affecting domain-joined systems.
- PAYLOAD changed wallpapers and lock screens, displayed ransom notes, distributed note files, and disabled local administrator accounts; the second GPO disabled Windows Firewall.
- The policies were created on April 13, 2026, and took effect when endpoints rebooted the next day. No Windows files were encrypted, and investigators found no resident malware or endpoint persistence.
- Data exfiltration from file servers and other systems was observed, and the stolen data was later published on the dark web. A PAYLOAD sample targeting ESXi on Linux servers was also found.
- Kaspersky recommends auditing directory-service changes, monitoring SYSVOL for unexpected changes, and restricting privileged GPO creation and linking. Its guidance also covers removing the malicious policies and hardening VPN access.
Article Details
- Victim Organization
- An unnamed manufacturing organization in the Middle East
- Incident Type
- Compromised-account access through FortiGate SSL VPN, followed by malicious Active Directory Group Policy changes, data exfiltration and encryptionless extortion
- Incident Date
- 2026-04-11
- Operational Impact
- Domain-root-linked GPOs disrupted domain-joined Windows workstations after reboot: ransom imagery and notes appeared, the local administrator account was disabled, and Windows Firewall was disabled on all profiles. Kaspersky confirmed no Windows file encryption or resident endpoint malware. Data exfiltration was observed from file servers and additional systems; the article says the data was later published on the dark web.
- Ransom Or Extortion
- Ransom notes, a logon banner and ransom imagery were deployed. The article describes extortion without confirmed Windows file encryption; it does not disclose a ransom amount.
- Claim Status
- confirmed
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| IPV4 | 104[.]164[.]55[.]46 | IP address listed in the article's indicators of compromise. |
| IPV4 | 104[.]28[.]162[.]228 | IP address listed in the article's indicators of compromise. |
| IPV4 | 104[.]28[.]163[.]162 | IP address listed in the article's indicators of compromise. |
| IPV4 | 146[.]70[.]117[.]239 | IP address listed in the article's indicators of compromise. |
| IPV4 | 149[.]102[.]229[.]154 | IP address listed in the article's indicators of compromise. |
| IPV4 | 192[.]42[.]116[.]12 | IP address listed in the article's indicators of compromise. |
| IPV4 | 192[.]42[.]116[.]50 | IP address listed in the article's indicators of compromise. |
| IPV4 | 192[.]42[.]116[.]52 | IP address listed in the article's indicators of compromise. |
| IPV4 | 192[.]42[.]116[.]56 | IP address listed in the article's indicators of compromise. |
| IPV4 | 192[.]42[.]116[.]97 | IP address listed in the article's indicators of compromise. |
| IPV4 | 37[.]19[.]210[.]12 | IP address listed in the article's indicators of compromise. |
| IPV4 | 64[.]190[.]76[.]14 | IP address listed in the article's indicators of compromise. |
| MD5 | 0108656a3e1ade6ca4f21b084f5e1208 | MD5 listed for killer.exe, a process-killer tool in the article's indicators of compromise. |
| MD5 | bea5e267f24d7da59f6821bffdbff293 | MD5 listed for kill.exe, a process-killer tool in the article's indicators of compromise. |
MITRE ATT&CK
T1005 · Data from Local SystemThe article maps observed exfiltration originating from file servers to this technique.T1078 · Valid AccountsA compromised valid domain credential was used for initial access.T1078.002 · Domain AccountsThe compromised account had domain-level GPO creation and linking rights.T1133 · External Remote ServicesThe actor authenticated through the victim's FortiGate SSL VPN.T1484.001 · Group Policy ModificationThe actor created and linked malicious GPOs at the domain root.T1491.001 · Internal DefacementThe PAYLOAD GPO replaced workstation wallpaper and lock-screen imagery with a ransom image.T1531 · Account Access RemovalThe PAYLOAD GPO disabled the local administrator account.T1562.004 · Disable or Modify System FirewallThe article associates this ID with the GPO that disabled Windows Firewall on all profiles.T1686 · Disable or Modify System FirewallThe article's ATT&CK mapping assigns firewall disablement through the win Firewall Off GPO to this ID.
Malware
Vendors
Products
Active DirectoryThe threat actor obtained domain admin-equivalent control of the organization’s Active Directory environment and authored a malicious Group Policy Object (GPO) named PAYLOAD, linking it at the domain root.ESXiThe only ransomware we found in this incident was PAYLOAD sample targeting ESXi on Linux servers.FortiGate SSL VPNInitial access. Threat actor authenticates to the FortiGate SSL VPN using a valid but compromised domain credential.Kaspersky Endpoint Detection and Response Experta large number of characteristic artifacts on the domain controller, enabling Kaspersky Endpoint Detection and Response Expert to promptly alert the user to anomalies in the infrastructure.Kaspersky SIEMTo protect organizations that use our Kaspersky SIEM system, we have prepared a package of correlation rules designed to help detect this type of malicious activity.Microsoft Windowsscreen, enforced a logon banner, and disabled the local administrator account across every domain-joined Windows workstation — all without dropping a ransomware binary or encrypting any data.Windows FirewallSecond GPO. GPO named win Firewall Off ({22099AD2-E062-4F56-B574-5099BBA4E7A6}) linked at the domain root, disabling Windows Firewall on all profiles.