• 3 minuti
  • Pubblicato

PAYLOAD ransomware turns Active Directory into a weapon

Barbara Carminati Autrice di cybersecurity e privacy QWERTYmag

Scritto da Barbara Carminati

PAYLOAD ransomware turns Active Directory into a weapon QWERTYmag © www.qwertymag.it
PAYLOAD ransomware turns Active Directory into a weapon © www.qwertymag.it

The PAYLOAD ransomware group has flipped the script, using Microsoft Active Directory Group Policy to freeze Windows systems and steal data-without dropping classic ransomware.

The old signs of ransomware don't apply here. The PAYLOAD group has shown that attackers can bring a company down without encrypting files or planting malware. By taking over Microsoft Active Directory Group Policy, they can wreck Windows networks from the inside. Defenders are left searching for clues and scrambling to respond.

Kaspersky's Global Emergency Response Team says a manufacturing firm in the Middle East was hit by this new kind of attack. The hackers got in through a stolen VPN account. They worked their way up until they had domain admin rights. With that access, they set up a fake Group Policy Object (GPO) called "PAYLOAD" and linked it to the domain root. That meant every Windows machine on the network was in their sights.

Unconventional tactics and invisible footprints

PAYLOAD didn't use ransomware files. Instead, they turned the company's own admin tools against it. The rogue GPO sent out ransom notes, changed desktop wallpapers, shut down local admin accounts, and turned off Windows Firewall everywhere. They added a second GPO, "win Firewall Off," to weaken defenses even more. These changes kicked in after a reboot, throwing the company into chaos.

This attack is hard to spot because there's no malware to find. No strange files. No active bad processes. Just a string of changes buried in Active Directory. Most endpoint security tools miss this. Incident responders are left with only the altered GPOs and the mess left on user machines.

PAYLOAD demonstrates that attackers can achieve ransomware-level disruption without encrypting files, simply by abusing legitimate Active Directory administrative tools. This marks a significant evolution in the threat landscape, requiring organizations to rethink their detection and response strategies.

Kaspersky SecurelistThreat Intelligence Report

Data exfiltration and public exposure

PAYLOAD didn't just cause disruption. The group stole sensitive data and leaked it on the dark web, making things worse. Their stealthy use of admin tools is similar to what Ryuk and LockBit have done before. But PAYLOAD didn't bother with file encryption at all. That's a new twist in ransomware tactics.

This attack comes as ransomware hits more Middle Eastern companies. A recent report shows cyber extortion is rising fast in the region. Attackers are now going after core IT systems instead of just dropping malware. That's a warning sign for defenders everywhere.

Defensive priorities for organizations

Kaspersky's advice is clear. Companies need to watch GPO changes in real time, lock down the SYSVOL directory, use multi-factor authentication for VPNs, limit who can change GPOs, and keep Active Directory audit logs in one place. These steps aren't optional anymore. They're needed to stop attackers from turning trusted admin tools into weapons.

The PAYLOAD attack shows a big gap in many security plans: the belief that threats always show up as files or processes. Now, ransomware groups are using legit infrastructure to attack. Defenders have to change their approach or risk missing attacks that leave almost no trace. Fileless ransomware isn't just a theory now. It's happening.

Italian companies should also keep an eye on updates from the Agenzia per la Cybersicurezza Nazionale (ACN), which regularly posts advice on Active Directory security and ransomware defenses for the national context.

Articoli correlati