← NEWS & INSIGHTS

NEWS / RESEARCH & ANALYSIS

PAYLOAD incident: extortion evidence inside Active Directory

Kaspersky GERT reports an April manufacturing-sector incident in which Group Policy changes disrupted Windows workstations and displayed ransom demands without encrypting their files.

Source published 2026-09-21Digital forensicsResearch briefing
Original publication preview: PAYLOAD incident: extortion evidence inside Active Directory
Kaspersky / Securelist ↗

Findings and evidence

Kaspersky GERT reports an April manufacturing-sector incident in which Group Policy changes disrupted Windows workstations and displayed ransom demands without encrypting their files. The investigators separately identified an ESXi ransomware sample and data theft.

Why it matters

The case broadens the evidence set beyond a ransomware executable. Preserve directory audit records, policy history and administrative changes, then correlate them with endpoint and file-server activity. Recovery planning needs to account for changes in the management plane.

Scope and limits

The absence of Windows file encryption applies to this investigated incident. It does not establish that every PAYLOAD deployment behaves the same way.

Primary source

Kaspersky / Securelist: original publication. Source published 2026-09-21. Brief prepared by websec.gr on 26 September 2026. This is an editorial research summary, not a claim of independent replication.

Search the lab

NEWS / FORENSICS / FIELD GUIDES ESC