← Back to feed
Breaches & RansomwareEmerging1 sourceSep 22, 2026 · 09:59via CyberInsider

PAYLOAD ransomware hijacks Windows Group Policy in encryption-less attacks

Brief

A PAYLOAD ransomware incident weaponized Microsoft Active Directory Group Policy to disrupt an organization’s Windows computers without deploying ransomware or encrypting files. Instead, the attackers used the company’s own administration infrastructure to display ransom notes, change wallpapers, deactivate local administrator accounts, and turn off Windows Firewall across the network.

Kaspersky’s Global Emergency Response Team (GERT) …

The post PAYLOAD ransomware hijacks Windows Group Policy in encryption-less attacks appeared first on CyberInsider .

Read more on CyberInsider