CTIPilot

Microsoft Active Directory Group Policy

product · product:microsoft-active-directory-group-policy single-source

Coverage timeline
1
first 2026-09-29 → last 2026-09-29
Peak priority
high
1 high
Sources cited
1
1 hosts
Sections touched
1
deep-dive
Co-occurring entities
2
see Co-occurring entities below
ATT&CK techniques
8
pinned v19.2 · see below

Hunting pivots

Releases covered
Microsoft Active Directory Group Policy

ATT&CK techniques

8 techniques observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-09-29/kaspersky-payload-gpo-encryptionless-ransomware · ATT&CK page ↗

T1133External Remote Services×1

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.

Evidence: 2026-09-29/kaspersky-payload-gpo-encryptionless-ransomware · ATT&CK page ↗

Persistence TA0003

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-09-29/kaspersky-payload-gpo-encryptionless-ransomware · ATT&CK page ↗

T1133External Remote Services×1

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.

Evidence: 2026-09-29/kaspersky-payload-gpo-encryptionless-ransomware · ATT&CK page ↗

Privilege Escalation TA0004

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-09-29/kaspersky-payload-gpo-encryptionless-ransomware · ATT&CK page ↗

T1484.001Domain or Tenant Policy Modification: Group Policy Modification×1

Adversaries may modify Group Policy Objects (GPOs) to subvert the intended discretionary access controls for a domain, usually with the intention of escalating privileges on the domain. Group policy allows for centralized management of user and computer settings in Active Directory (AD). GPOs are containers for group policy settings made up of files stored within a predictable network path `\<DOMAIN>\SYSVOL\<DOMAIN>\Policies\`.

Evidence: 2026-09-29/kaspersky-payload-gpo-encryptionless-ransomware · ATT&CK page ↗

Stealth TA0005

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-09-29/kaspersky-payload-gpo-encryptionless-ransomware · ATT&CK page ↗

Defense Impairment TA0112

T1484.001Domain or Tenant Policy Modification: Group Policy Modification×1

Adversaries may modify Group Policy Objects (GPOs) to subvert the intended discretionary access controls for a domain, usually with the intention of escalating privileges on the domain. Group policy allows for centralized management of user and computer settings in Active Directory (AD). GPOs are containers for group policy settings made up of files stored within a predictable network path `\<DOMAIN>\SYSVOL\<DOMAIN>\Policies\`.

Evidence: 2026-09-29/kaspersky-payload-gpo-encryptionless-ransomware · ATT&CK page ↗

T1686Disable or Modify System Firewall×1

Adversaries may disable or modify host-based or network firewalls to impair defensive mechanisms and enable further action. Once an adversary has gathered sufficient privileges, they can tamper with firewall services, policies, or rule sets to remove restrictions on inbound or outbound traffic. For example, this may include turning off firewall profiles, altering existing rules to permit previously blocked ports or protocols, or adding new rules that create covert communication paths (e.g., adding a new firewall rule for a well-known protocol (such as RDP) using a non-traditional and potentially less securitized port.

Evidence: 2026-09-29/kaspersky-payload-gpo-encryptionless-ransomware · ATT&CK page ↗

Collection TA0009

T1005Data from Local System×1

Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.

Evidence: 2026-09-29/kaspersky-payload-gpo-encryptionless-ransomware · ATT&CK page ↗

Impact TA0040

T1491.001Defacement: Internal Defacement×1

An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems. This may take the form of modifications to internal websites or server login messages, or directly to user systems with the replacement of the desktop wallpaper. Disturbing or offensive images may be used as a part of Internal Defacement in order to cause user discomfort, or to pressure compliance with accompanying messages. Since internally defacing systems exposes an adversary's presence, it often takes place after other intrusion goals have been accomplished.

Evidence: 2026-09-29/kaspersky-payload-gpo-encryptionless-ransomware · ATT&CK page ↗

T1531Account Access Removal×1

Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials, revoked permissions for SaaS platforms such as Sharepoint) to remove access to accounts. Adversaries may also subsequently log off and/or perform a System Shutdown/Reboot to set malicious changes into place.

Evidence: 2026-09-29/kaspersky-payload-gpo-encryptionless-ransomware · ATT&CK page ↗

T1657Financial Theft×1

Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, "pig butchering," bank hacking, and exploiting cryptocurrency networks.

Evidence: 2026-09-29/kaspersky-payload-gpo-encryptionless-ransomware · ATT&CK page ↗

Story timeline

  1. 2026-09-29An attacker achieves domain-wide ransomware impact on every Windows workstation with zero encryption binary and zero endpoint persistence, entirely through a malicious Group Policy Object named "PAYLOAD" linked at the domain root, while a separate PAYLOAD binary hits ESXi/Linux servers and exfiltrated data surfaces on the dark web
    deep-diveKaspersky GERT: a Group Policy Object was the whole ransomware on Windows, and it left nothing for an EDR to alert on until the wallpaper changed

Where this entity is cited

  • deep-dive1

Source distribution

  • securelist.com1 (100%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Microsoft Active Directory Group Policy (1)

2026-09-29 · view entry permalink →

HIGHNATOB2

An attacker achieves domain-wide ransomware impact on every Windows workstation with zero encryption binary and zero endpoint persistence, entirely through a malicious Group Policy Object named "PAYLOAD" linked at the domain root, while a separate PAYLOAD binary hits ESXi/Linux servers and exfiltrated data surfaces on the dark web

Kaspersky's Global Emergency Response Team (GERT) reconstructs an April 2026 incident at a Middle East manufacturing organization in which an attacker authenticated to a FortiGate SSL VPN using a compromised credential of unconfirmed provenance, obtained Group-Policy-write privileges via an unconfirmed escalation path, and authored a malicious Group Policy Object named "PAYLOAD" linked at the domain root (Kaspersky Securelist, 2026-09-21). On every Windows workstation, the GPO used only native client-side extensions (CSEs) to achieve the operation's whole visible impact, with no encryptor of any kind: the Files CSE dropped a read-only ransom note to every desktop and drive root; the Registry CSE rewrote the Windows logon legal-notice banner to ransom text; the Personalization/Desktop policy set a SYSVOL-hosted ransom image as every machine's lock screen and wallpaper; and Security Settings CSE (GptTmpl.inf) disabled the local Administrator account fleet-wide, alongside a second GPO disabling Windows Firewall domain-wide.

Because computer-configuration GPO settings apply only on reboot or a policy refresh cycle, the malicious policy sat cached and dormant for a full day between authoring (13 April) and mass visible impact (14 April); during that window, data exfiltration from file servers and several additional systems proceeded unnoticed. On the Windows domain-joined estate specifically, Kaspersky's forensic reconstruction found no files encrypted, no ransomware binary resident on disk, and no endpoint persistence mechanism of any kind: a detection program keyed on ransomware executables, encryption behavior, or process-level anomalies would have produced zero alerts until the ransom wallpaper appeared, post-reboot, on every affected desktop simultaneously. Kaspersky is explicit that this no-binary finding is scoped to that Windows activity: "The only ransomware we found in this incident was PAYLOAD sample targeting ESXi on Linux servers" (Kaspersky Securelist, 2026-09-21): a genuine ransomware binary was deployed, but against the organization's ESXi/Linux servers, a separate track from the GPO-only attack on Windows. The exfiltrated data was later published on the dark web, per Kaspersky's own account, confirming the extortion followed through beyond the operational-disruption phase. Kaspersky does not treat the absence of Windows-side encryption as settled: it assesses "with moderate confidence that the missing encryption reflects one of two scenarios: (1) a deliberate decision to stay below the irreversible data destruction threshold while preserving the option of a follow-on encryption phase, or (2) an operation interrupted before full execution" (Kaspersky Securelist, 2026-09-21).

Triage: for the Windows-side GPO attack, the discriminator is not endpoint behavior but Group Policy content and change history, since no encryption or binary execution occurs on those hosts. A domain-root or high-scope GPO created or modified outside a change-managed window, especially one touching the Files, Registry, Security Settings or Personalization CSEs simultaneously, is the signal; ordinary administrative GPO changes rarely touch all four categories in a single object, and a GPO disabling the local Administrator account or Windows Firewall domain-wide has essentially no benign justification. On ESXi/Linux hosts, the discriminator is the ordinary one for ransomware: an actual PAYLOAD binary execution.

an encryptionless, binary-less operation that abused Active Directory mechanisms for managing Group Policy Objects

The only ransomware we found in this incident was PAYLOAD sample targeting ESXi on Linux servers. Besides that, data exfiltration was observed originating from the file servers and several additional systems, and was later published on the dark web.

we assess with moderate confidence that the missing encryption reflects one of two scenarios: (1) a deliberate decision to stay below the irreversible data destruction threshold while preserving the option of a follow-on encryption phase, or (2) an operation interrupted before full execution

Kaspersky Securelist (Kaspersky GERT) 2026-09-21
threat29 Sep 05:00Zsingle-sourceOpen finding ↗