• 3 minuti
  • Pubblicato

Ransomware locks company network using Windows tools and stolen accounts

Barbara Carminati Autrice di cybersecurity e privacy QWERTYmag

Scritto da Barbara Carminati

Ransomware locks company network using Windows tools and stolen accounts QWERTYmag © www.qwertymag.it
Ransomware locks company network using Windows tools and stolen accounts © www.qwertymag.it

A manufacturing firm in the Middle East was crippled by ransomware that never used encryption. Instead, attackers hijacked privileged accounts and standard Windows features to lock workstations, display ransom notes, and leak stolen data online.

Workstations at a manufacturing company in the Middle East froze without warning. Employees saw locked screens and ransom notes. But there was no sign of the usual ransomware encryption.

This was not a glitch or a typical malware attack. Kaspersky Lab says the attackers broke in by stealing privileged accounts. They used standard remote access tools and VPNs, moving through the network like real IT staff. Their actions looked just like normal admin work.

Active Directory takeover: attackers use company tools against itself

The turning point came when the attackers took over Active Directory. This system controls device management in most companies. They set up a fake Group Policy called Payload. Normally, Group Policy is used for mass updates. Here, it became a weapon. With one update, the attackers changed desktop wallpapers, locked screens, posted ransom notes, and even disabled admin accounts. The company could not fight back.

No files were encrypted. The attack used only trusted Windows features. Antivirus scans found nothing. Once the policy spread, every connected workstation was hit. IT teams had no easy way to spot or undo the damage. Kaspersky's analysis found no malware files, no persistence, and no active malicious processes. This "encryptionless" attack was hard to trace and even harder to stop.

When attackers hijack central network rules, traditional endpoint malware scanning alone may be insufficient. Organizations must enforce tighter control of administrative credentials, deploy phishing-resistant MFA, and continuously monitor Group Policy changes to defend against such stealthy attacks.

Elsayed ElrefaeiKaspersky Security Expert

Double extortion: locked systems and leaked data

While the company tried to recover, the attackers pushed harder. They stole sensitive data and posted it on the dark web. The threat of exposure added pressure to pay up. Kaspersky Lab points out that ransomware groups are moving away from encryption. Now, they focus on stealing data, blocking access, and public shaming. This shift is also seen in recent Reuters reports on extortion tactics.

This change matches what's happening in the cybercrime world. Even big ransomware gangs are now targets. As reported earlier, rival groups have started hijacking each other's leak sites. No one is safe, not even the criminals themselves.

What companies must do now

This attack is a warning for corporate security. Defenses that only look for malware or file encryption are no longer enough. Attackers now use the same tools as IT staff. When they blend in, old safeguards fail.

Scanning for viruses or blocking suspicious files is not enough. Companies need to rethink how they manage identities, control privileges, and watch what admins do inside the network. The New Zealand National Cyber Security Centre says better logging and auditing on domain controllers is now critical. Active Directory itself is a prime target. Ransomware is no longer just about locking files. It's about taking over the very systems meant to protect the company. Only those who adapt will avoid being the next victim.

Articoli correlati