A PAYLOAD ransomware affiliate compromised a Middle Eastern manufacturing organization in April 2026 using a valid domain credential through a FortiGate SSL VPN. After obtaining domain-admin-equivalent Group Policy permissions, the actor linked malicious GPOs at the Active Directory domain root to distribute ransom notes, alter endpoint wallpapers and lock screens, set a ransom logon banner, disable local Administrator accounts, and disable Windows Firewall. Investigators found no encrypted Windows files, persistent endpoint malware, or active malicious processes; Active Directory and SYSVOL served as the attack control plane. The attackers exfiltrated data from file servers and other systems, later publishing it on the dark web, while an ESXi-targeting PAYLOAD sample was identified on Linux servers.
The intrusion reflects the growth of encryptionless extortion, in which operators steal data and coerce victims without necessarily deploying file-encrypting malware. Extortion activity reached 6,182 reported incidents in 2025, while ransomware leak sites claimed 4,737 victims; attackers commonly combine stolen credentials, privilege escalation, legitimate administrative tooling, and centralized deployment mechanisms such as Group Policy. Organizations should prioritize MFA and monitoring for remote access, least-privilege controls over GPO administration, auditing of domain-root GPO changes and SYSVOL, rapid credential containment, and defenses against data exfiltration alongside endpoint ransomware controls.

TTPs, infrastructure, and targeting history in one profile.
11 events from the most recent confirmed update back to the earliest known activity.
Incident responders confirmed that affected Windows endpoints had not undergone file encryption and contained no resident endpoint malware. They found the Active Directory GPO link, rather than an endpoint-resident component, served as the persistence mechanism.
Kaspersky's Global Emergency Response Team began responding to the PAYLOAD incident at the affected manufacturer.
As endpoints rebooted or refreshed policy, the malicious GPO settings applied, displaying PAYLOAD ransom imagery and notes and causing operational disruption. The policies had been cached on endpoints the previous day.
The actor exfiltrated data from the manufacturer's file servers and several additional systems. The stolen data was subsequently published on the dark web.
The actor created and linked the PAYLOAD GPO and a separate "win Firewall Off" GPO at the Active Directory domain root. The policies distributed ransom notes and imagery through SYSVOL, disabled local Administrator accounts, and disabled Windows Firewall across profiles.
The PAYLOAD ransomware operation authenticated to a Middle Eastern manufacturing victim's FortiGate SSL VPN using a valid compromised domain credential. Investigators could not reconstruct how the credential was initially compromised because of insufficient FortiGate logging.
A Snakefly (Cl0p) campaign targeting Oracle E-Business Suite users came to light. The group exploited CVE-2025-61882, a critical vulnerability allowing unauthenticated remote code execution on vulnerable EBS systems.
The RansomHub ransomware-as-a-service operation, also known as Greenbottle, shut down.
Leak-site data recorded 4,737 ransomware claims during 2025, compared with 4,701 in 2024. Including encryptionless cases, total extortion attacks reached 6,182, a 23% increase over 2024.
LockBit (also known as Syrphid) collapsed or was significantly disrupted and did not successfully rebuild despite later attempts.
Investigators identified an ESXi-targeting PAYLOAD ransomware sample on Linux servers in the victim environment, although the investigation did not establish that it was used to encrypt systems.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 14 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
securelist.ru
Open sourcesecurelist.com
Open sourcemicrosoft.com
Open sourcesecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.