Executive summary In April 2026, we at Kaspersky’s Global Emergency Response Team (GERT) responded to a security incident at a manufacturing organization in the Middle East. The threat actor obtained domain admin-equivalent control of the organization’s Active Directory environment and authored a malicious Group Policy Object (GPO) named PAYLOAD, linking it at the domain root.
Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO
About this summary. This is a short, independently written summary of an article first published by Kaspersky Securelist. Cyber Security News did not report or verify the underlying story. Read the original: https://securelist.com/tr/payload-ransomware-via-group-policy/121335/

Source attribution: headline and facts are from Kaspersky Securelist (securelist.com). Summary method: excerpt of the source description. See our source attribution policy.




