# Digital forensics

Published articles for Digital forensics.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO

DevFeed: [Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO](<https://devfeed.tech/articles/group-policy-hijacked-payload-ransomware-weaponizes-active-directory-gpo-55757.md>)

Original publisher: [Read original article](<https://securelist.com/tr/payload-ransomware-via-group-policy/121335/>)

Author: Ahmad Zaidi Said, Elsayed Elrefaei, Kaspersky Security Services

Published: 2026-09-21T10:00:40Z

Content type: article

Language: en

Sources: [Securelist](<https://devfeed.tech/sources/securelist.md>)

Topics: [active directory](<https://devfeed.tech/topics/active-directory.md>), [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Security](<https://devfeed.tech/topics/security.md>), [incident](<https://devfeed.tech/topics/incident.md>), [enterprise deployment](<https://devfeed.tech/topics/enterprise-deployment.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [data-exfiltration](<https://devfeed.tech/tags/data-exfiltration.md>), [data-leaks](<https://devfeed.tech/tags/data-leaks.md>), [data-theft](<https://devfeed.tech/tags/data-theft.md>), [detection](<https://devfeed.tech/tags/detection.md>), [detection-and-response](<https://devfeed.tech/tags/detection-and-response.md>), [detection-engineering](<https://devfeed.tech/tags/detection-engineering.md>), [digital-forensics](<https://devfeed.tech/tags/digital-forensics.md>), [full](<https://devfeed.tech/tags/full.md>), [gpo](<https://devfeed.tech/tags/gpo.md>), [group-policies](<https://devfeed.tech/tags/group-policies.md>), [incident](<https://devfeed.tech/tags/incident.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [kaspersky](<https://devfeed.tech/tags/kaspersky.md>), [large](<https://devfeed.tech/tags/large.md>), [linux](<https://devfeed.tech/tags/linux.md>), [medium](<https://devfeed.tech/tags/medium.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [thumbnail](<https://devfeed.tech/tags/thumbnail.md>)

### AI overview

Kaspersky describes a 2026 incident in which an attacker with domain administrator-equivalent control abused an Active Directory Group Policy Object named PAYLOAD to affect Windows workstations across a manufacturing organization. The operation delivered ransom notes and altered system settings without deploying a ransomware binary or encrypting Windows data; data exfiltration was also observed.

### Source excerpt

Kaspersky GERT experts dive into the technical incident analysis of PAYLOAD ransomware: an encryptionless, binary-less operation that abused Active Directory mechanisms for managing Group Policy Objects.