GLOBAL   NEWS   PAKISTAN

Kaspersky Uncovers Stealthy ‘Payload’ Ransomware Campaign

Kaspersky Uncovers Stealthy 'Payload' Ransomware Campaign

Islamabad (GNP):  Kaspersky’s Global Emergency Response Team (GERT) has released a new report examining a sophisticated tactic used by the Payload ransomware family. Identified during an incident response at a manufacturing company in the Middle East, the attack marks a notable shift in cybercriminal strategy — attackers gained full control of the company’s network and forced its systems to lock up, display ransom notes, and change desktop wallpapers, all without deploying a traditional ransomware encryptor.

This incident reflects a trend previously flagged in Kaspersky’s State of Ransomware 2026 report: cybercriminals are increasingly moving away from conventional file encryption in favor of “encryptionless extortion,” which centers on causing immediate operational disruption and leaking stolen sensitive data on the dark web rather than relying on encryption keys to extract ransom payments.

Rather than deploying complex malware to breach the network, the attackers bypassed initial security defenses by obtaining administrator-level credentials — likely through phishing — which they used to log directly into the corporate network via standard remote-access and VPN channels. The intrusion went undetected, with the attackers appearing to security systems as legitimate IT staff performing routine tasks.

The hackers then leveraged the company’s own trusted administrative tools to carry out the attack, targeting Active Directory — the core infrastructure of the corporate network — and creating a malicious Group Policy Object (GPO) rule.

GPOs allow network administrators to instantly apply configuration settings across thousands of employee computers. Because Group Policy is a legitimate, highly privileged administrative function, malicious changes made through compromised accounts can closely mimic normal IT activity. By embedding the entire attack within a malicious GPO rule labeled “PAYLOAD,” the attackers operated undetected. The rule immediately disabled local administrator accounts, distributed ransom notes, and altered every affected computer’s desktop wallpaper and lock screen to display a ransom message as soon as systems processed the updated policy.

The attackers primarily focused on stealing valuable corporate data. Once the theft was complete and the administrative lockouts triggered, the stolen data was ultimately published on the dark web to complete the extortion scheme.

Elsayed Elrefaei, a security expert at Kaspersky’s Global Emergency Response Team, explained that the tactics behind the PAYLOAD attack represent a further evolution in cybercriminal methods. He noted that when attackers take control of central network policies, conventional endpoint malware scanning alone may not be enough while the malicious Group Policy remains active, and stressed that organizations need to prioritize blocking malicious policies at their source, tightly restricting administrative credentials, and shifting toward behavior-based monitoring rather than relying solely on malware detection.

Also read: Shaza Formally Inaugurates ‘Innovation Hive’ Estb by USEFP

Kaspersky recommends that network administrators closely monitor all GPO creation and modification activity, with security alerts configured to trigger immediately whenever a new rule is linked to the root of the corporate network. The company also advises requiring phishing-resistant multi-factor authentication — such as physical security keys — for any access to administrative systems or VPN entry points, enforcing strict administrative boundaries so general IT administrators don’t hold master access to every workstation and server, and limiting highly privileged Domain Admin accounts to dedicated, isolated systems only.

Field Correspondent Sohail Majeed
+ posts

Sohail Majeed is a Special Correspondent at The Diplomatic Insight. He has twelve plus years of experience in journalism & reporting. He covers International Affairs, Diplomacy, UN, Sports, Climate Change, Economy, Technology, and Health.