News

Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO

  • Ahmad Zaidi Said, Elsayed Elrefaei--Securelist.com
  • published date: 2026-09-21 10:00:40 UTC

Kaspersky GERT experts dive into the technical incident analysis of PAYLOAD ransomware: an encryptionless, binary-less operation that abused Active Directory mechanisms for managing Group Policy Objects.

Continue Reading at Securelist.com →