Malware
PAYLOAD
- First Reported
- Sep 21, 2026
- Latest Reported
- Sep 21, 2026
Reported Context (1)
- The threat actor obtained domain admin-equivalent control of the organization’s Active Directory environment and authored a malicious Group Policy Object (GPO) named PAYLOAD, linking it at the domain root. PAYLOAD Ransomware Used Malicious Active Directory Policies to Disrupt a Manufacturing Firm
MITRE ATT&CK (9)
Vendors (1)
Products (7)
Tools (2)
Industries (1)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.