IN April 2026, Kaspersky’s Global Emergency Response Team investigated a ransomware-related incident at a manufacturing organisation in the Middle East in which attackers gained domain administrator-equivalent control of Active Directory. They created and linked a malicious Group Policy Object (GPO), named PAYLOAD ({C897F2C7-C2AC-4E6F-BF48-58036FF29E79}), at the domain root.
The policy distributed ransom notes, changed wallpapers and lock screens, displayed a logon warning and disabled local administrator accounts across domain-joined Windows systems. A second GPO, “win Firewall Off” ({22099AD2-E062-4F56-B574-5099BBA4E7A6}), disabled Windows Firewall on all profiles. The attackers entered through a FortiGate SSL VPN using a compromised valid domain credential; the original theft method and subsequent privilege escalation could not be established because relevant logs were insufficient.
Kaspersky said no Windows files were encrypted, no ransomware binary was found on affected endpoints, and no malicious processes or conventional persistence mechanisms were present. Instead, the attack was embedded in Active Directory and SYSVOL, allowing trusted Group Policy processing to deliver the impact after most machines rebooted on 14 April, a day after the policies were created. Data exfiltration was observed from file servers and other systems and was later published on the dark web.
Investigators did find PAYLOAD malware targeting ESXi on Linux servers, but did not confirm that wider techniques such as BYOVD, event-log clearing or ESXi security-policy weakening were used in this incident.
Kaspersky recommends removing both malicious GPOs, cleaning the staged SYSVOL files, resetting compromised credentials and forcing a clean policy refresh. Defenders should enable and centrally monitor Active Directory change events 5136, 5137 and 5141, watch for unexpected SYSVOL changes, and alert on domain-root `gPLink` modifications by unauthorised accounts.