⚠️ Region Alert: UAE/Middle East
Kaspersky’s Global Emergency Response Team (GERT) recently investigated a unique ransomware incident at a manufacturing organization in the Middle East involving the PAYLOAD group. The threat actor achieved domain admin-equivalent control and utilized a malicious Group Policy Object (GPO) to distribute ransom notes, hijack wallpapers, and disable local administrator accounts across all Windows workstations. Notably, no ransomware binaries were dropped and no files were encrypted on Windows systems, representing a sophisticated move toward encryptionless extortion and living-off-the-land (LotL) tactics within Active Directory.
The attack exploited the GPO mechanism as a signed, privileged distribution channel, effectively bypassing traditional endpoint detection and response tools that do not typically inspect GPO modifications. This strategy allowed the attackers to maintain persistence and cause operational disruption without triggering file- or process-based detection stacks. To combat such threats, organizations must shift focus toward directory service change auditing, SYSVOL integrity monitoring, and the implementation of tiered administrative models to protect critical Active Directory infrastructure.
Top comments (0)