
PAYLOAD Ransomware Weaponizes Active Directory Group Policy for Domain-Wide Attacks
hacker attacksmalwareransomwareActive Directorybackupinitial access brokerkasperskypasswordphishingsecurity awarenessVPN
Kaspersky analyzed an incident involving a ransomware called PAYLOAD that weaponized Active Directory Group Policy to attack an entire domain simultaneously. The attack method left no malware on PCs, no encrypted files, and no suspicious processes to detect. The attackers transformed Active Directory Group Policy, a trusted Windows administration tool, into an extortion mechanism. This approach represents a technique where the infrastructure itself becomes the attack vector rather than traditional malware deployment methods.