⚠️ Region Alert: UAE/Middle East
In April 2026, Kaspersky’s Global Emergency Response Team (GERT) investigated a security incident at a manufacturing organization in the Middle East where threat actors weaponized Active Directory Group Policy Objects (GPOs). The attackers created a malicious GPO named "PAYLOAD" to deliver ransom notes, hijack desktop wallpapers, and disable local administrator accounts across all domain-joined Windows workstations. This attack was notable for achieving domain-wide disruption and extortion without deploying a single ransomware binary or encrypting any data on Windows endpoints.
This case exemplifies two emerging trends: the abuse of trusted Active Directory infrastructure for "living-off-the-land" attacks and the rise of encryptionless extortion. By using GPOs, the attackers bypassed traditional file- and process-based detection stacks. While Windows systems remained unencrypted, the actors targeted ESXi Linux servers with ransomware and engaged in data exfiltration. The incident underscores the critical need for directory service auditing and integrity monitoring of the SYSVOL share to detect administrative tool abuse.
Top comments (0)