Skip to content

Security1 publisher2 min readPublished

A single Group Policy Object delivered the whole extortion stage at a Middle East manufacturer

Kaspersky's responders found no encrypted files and no malware on disk across the Windows estate of a Middle East manufacturer in April 2026. The impact arrived through one Group Policy Object linked at the domain root.

The Watch · Security desk

Illustration accompanying A single Group Policy Object delivered the whole extortion stage at a Middle East manufacturer

What happened

  • Kaspersky's Global Emergency Response Team responded in April 2026 to an incident at a Middle East manufacturer where the actor held domain admin-equivalent control and authored a GPO named PAYLOAD at the domain root.
  • That one object pushed ransom notes, hijacked wallpaper and lock screens, enforced a logon banner and disabled the local administrator account on every domain-joined Windows workstation.
  • Responders confirmed no encrypted Windows files, no malicious binaries on disk, no endpoint persistence and no malicious processes running when they analysed the environment.
  • The only ransomware sample found targeted ESXi on Linux servers, and data taken from the file servers and other systems was later published on the dark web.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • capability An intruder with domain admin now has a signed, SYSTEM-privileged delivery path that most EDR products are built not to read, so domain-wide impact lands with nothing for a file or process detection to catch.
  • constraint Reimaging workstations does not undo this attack: the policy object sits in Active Directory and SYSVOL and keeps applying, so recovery work moves into the directory.
  • decision Security teams whose alerting rests on file and process events have to fund change auditing on GPO creation and domain-root links, or the first indicator is the wallpaper at the next reboot.
  • contradiction The case complicates the encryptionless-extortion reading: Windows data was never encrypted, yet the same operation still shipped a PAYLOAD encryptor for ESXi.

A GPO is two pieces: a Group Policy Container in Active Directory and a Group Policy Template in SYSVOL [8]. Where the container is linked decides the reach, and a link at the domain root applies to every user and computer object beneath it [9]. Clients apply policy in a trusted, high-privilege context, and cleaning an endpoint does not remove the policy [10]. Kaspersky's Global Emergency Response Team said the entire attack lived inside Active Directory [14].

Five settings came out of the one object: the ransom note, the desktop wallpaper, the lock screen, a logon banner, and the disabled local administrator account [18]. None of them needed a binary on disk [3].

GPO abuse in ransomware operations is documented. Microsoft observed Ryuk operators distributing ransomware through Group Policy, SYSVOL startup items and PsExec; LockBit affiliates modified SYSVOL policy files including ScheduledTasks.xml; BlackCat/ALPHV operators created scheduled tasks through GPOs to deploy ransomware [11]. In those cases the policy object launched a payload, and Kaspersky describes PAYLOAD as using GPO Preferences and policy settings for impact itself [12].

Group Policy is signed, allowlisted and SYSTEM-privileged, and Kaspersky said the majority of endpoint detection and response tools are designed not to inspect it [7]. The GERT writeup put the consequence this way: "an organization whose detection strategy depends on catching a ransomware executable would have seen nothing until the first endpoint rebooted and the ransom wallpaper appeared" [13].

The encryptor has not left the toolkit. The only ransomware sample responders found targeted ESXi on Linux servers [5], so the encryption in this incident happened at the hypervisor layer while Windows files stayed intact [19].

Leverage came from the data. Exfiltration ran from the file servers and several additional systems, and the stolen data was later published on the dark web [6]. Kaspersky places the case in the encryptionless extortion category and said industry telemetry shows extortion-only incidents growing significantly year on year, without giving a figure [16].

The way in was a compromised valid account authenticating through the organization's FortiGate SSL VPN, mapped to ATT&CK T1078 and T1133 [15]. Between that login and the wallpaper there was no file event and no process event to alert on [4]. The telemetry left is in the directory: GPO creation, link changes at the domain root, and writes into SYSVOL [8]. Remediation happens in Active Directory and SYSVOL, because endpoint cleanup leaves the object in place [10]. The published account does not attribute the intrusion to a named group [17].

What to watch

  • Whether other responders report PAYLOAD GPOs linked at the domain root in additional victim environments.
  • Whether the PAYLOAD ESXi encryptor turns up in cases without an accompanying Group Policy impact stage.
  • Whether Kaspersky or Microsoft publish detection logic for domain-root GPO creation and SYSVOL writes tied to this activity.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories