Kaspersky’s Global Emergency Response Team identified a PAYLOAD extortion campaign whose operators took control of an Active Directory environment without deploying ransomware or encrypting files. The attackers used a malicious Group Policy Object (GPO) to distribute a ransom note, alter workstation wallpapers and lock screens, display a login banner, and disable local administrator accounts. The incident illustrates how attackers can exploit centralized administrative control to pressure victims without relying on encryption.
Kaspersky described the campaign against the backdrop of evolving ransomware tactics in 2026, highlighting extortion based on infrastructure control and threats to expose confidential information. Backups can reduce the leverage of file encryption but cannot eliminate the reputational, security, and regulatory consequences of stolen data; the supplied reporting does not establish whether data was stolen in this incident. Recommended defenses include regular backups, prompt patching, multifactor authentication, endpoint monitoring, external exposure management, least privilege, and employee training. For defenders, the malicious GPO also underscores the importance of monitoring changes to domain policies and protecting privileged Active Directory access.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
Kaspersky’s Global Emergency Response Team discovered PAYLOAD during an incident investigation. The attackers used their control of the victim’s infrastructure and access to confidential information as leverage rather than demanding payment for decryption.
PAYLOAD operators took control of a victim organization’s Active Directory environment without deploying ransomware or encrypting files. They used a malicious Group Policy Object to distribute a ransom note, change workstation wallpapers and lock screens, display a login banner, and disable local administrator accounts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
kaspersky.com
Open sourcekaspersky.ru
Open sourcesecurelist.ru
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.