Kaspersky’s GERT team spent this week picking apart a ransomware family named PAYLOAD that treats Active Directory like a staffing agency. The operators write Group Policy Objects and let your domain clock in for them. Disk stays boring. Temp stays empty. If your cybersecurity program still grades itself on blocked binaries, this is the week that score starts lying to you.

Kaspersky analysis graphic for PAYLOAD ransomware delivered through Group Policy
PAYLOAD lives in Group Policy, which is a software distribution network you already paid for.

Quiet dashboards are how cybersecurity sleeps through GPO

PAYLOAD’s designers made a cynical bet, and it is a good one. Kaspersky describes an encryptionless, binary-less operation that abuses the same Active Directory mechanisms you use to manage Group Policy. Your threat detection stack is still mostly a file problem. Hashes. Command lines. Parent-child process trees. A signed Microsoft client applying policy is none of those until a workstation checks in. By then the domain has already done the attacker’s job with software every laptop trusts.

You already know what GPO can touch. Logon scripts. Immediate scheduled tasks. Registry. Restricted groups. Software installation. Windows Firewall policy. An attacker who can create or link a GPO inherits that catalog in one object. A privileged session is the whole prerequisite. Your VPN brute-force logs can stay quiet the entire time.

I have watched teams dump weeks into endpoint threat-protection tuning while the Default Domain Policy ACL still includes a nested group nobody can explain. That is a gift with a ribbon on it. PAYLOAD’s operators collect gifts like that.

SYSVOL is a software distribution network you already paid for. Replication will even do the fan-out. A hostile GPO created in one site will show up in the others on your normal cadence, which means dwell time can look like “AD is healthy” on a replication dashboard.

The operational tell is authorship, not malware theater. New GPO GUIDs in the directory. Unexpected links on an OU that has been quiet for a year. SYSVOL writes outside your change window. gpt.ini version numbers jumping on a Friday night. A logon script that was not in the share on Monday. Plenty of SIEMs already ingest Directory Service events. If nobody built a detection around GPO creation, GPO linking, and SYSVOL churn, those events are furniture.

Defense in depth that stops at the laptop is incomplete here. The workstation is the delivery surface. The control plane is the domain. Treat GPO editors the way you treat domain admins, because for a lot of blast radius they are the same people.

Agents and IAM keys fail the same way

Dark Reading put a cousin of this failure on the front page this week. AI agents can trigger runaway costs because unbounded consumption sits sixth on OWASP’s Top 10 for LLM Applications. An agent with tool access and no spend cap will loop, retry, and fan out until finance notices. You would not hand a contractor a corporate card with no limit. Plenty of teams just did that with an API key and a prompt.

Data center compute racks illustrating unbounded cloud and AI consumption costs
Unbounded workers spend money. Unbounded GPOs spend your domain.

Unit 42 walked through how AWS uses managed policies to neutralize exposed IAM credentials, wrapping the response with GitHub secret scanning and CloudTrail monitoring. A policy object can slam a door. That same object can lock every admin out of the tenant if you swing it without a break-glass path. Cloud and on-prem are rhyming at you.

You already run workers that can rewrite production. Group Policy. IAM. Agents that call APIs with the keys you left in the environment. Cyber security programs keep buying sensors for the edge while the things that can rewrite the estate sit on inherited rights and default quotas. The invoice arrives as a ransom note, a cloud bill, or a Monday morning where nobody can log in.

Privileged automation without a kill switch is an incident waiting for a calendar.

Do the unglamorous domain work today

If you manage a domain this week, start with who can author policy. Dump every principal with Create GPO, Edit settings, Delete, and Link rights. Nested groups count. Service accounts count. That stale IT_Contractors group from 2019 counts. Remove anyone who cannot explain why they still have the ACE. Then turn on auditing for GPO creation, modification, linking, and SYSVOL writes, and page a human when those fire outside a change window.

Finish these before the next change freeze:

  • Export GPO ACLs and OU links; treat unexplained create, edit, or link rights as an incident, not a cleanup ticket.
  • Alert on new GPO GUIDs, unexpected SYSVOL writes, and gpt.ini version jumps, especially on Default Domain Policy and Default Domain Controllers Policy.
  • Disable or unlink GPOs that have not applied in months; stale policy is a quiet place to hide a scheduled task.
  • Put GPO admins on a dedicated tier, separate from mailbox and workstation logons, and require a checked-out admin identity for policy work.
  • Confirm you have a break-glass account that does not depend on the GPO you might have to revert.

Security hardening of Active Directory is weekly work, not a project you closed in 2022. Review GPO diffs the way you review firewall rule diffs. Use the GPMC reports you already have, or Get-GPOReport, and keep a known-good export. Test rollback in a lab OU so the first time you revert SYSVOL is not during an outage. Internet-facing RDP and SSH still eat brute-force all day; ipban soaks that noise up, and IPBan Pro is fine if you want the commercial extras, so your people hunt Directory Services events instead of login spam. That is perimeter hygiene. GPO ownership is a separate job.

Cloud identity research overview illustrating policy-based lockdown of compromised credentials
Managed policies can neutralize a stolen cloud key. You need the on-prem equivalent for GPO rights.

If you image one laptop, you already lost

Incident response for PAYLOAD-shaped operations starts in the directory. Isolate a laptop if you must. Then treat the domain as compromised until GPO version history, SYSVOL timestamps, OU links, and privileged group membership say otherwise.

Pull the GPO that changed. Read the actual settings. Scripts, immediate scheduled tasks, restricted groups, registry values that disable security products, Windows Firewall rules that open a path you never approved. Roll back from a known-good backup of SYSVOL and the directory. Editing a hostile GPO live is a race against someone who still has the same ACE you are staring at.

Reset credentials for anyone who could have authored that object. Tickets, service accounts, and the help desk identity that still has delegated rights on an OU. Recipients of a new Restricted Groups policy may now be domain admins. Check. Users will see an “IT policy update” and trust it, because that is what Group Policy has always looked like from the desktop. Your comms plan should say the policy engine is in scope, not only “a malware incident on some PCs.”

Name a domain controller as an evidence source in the playbook, not only as a patient. If the first artifact you collect is a memory dump from a receptionist PC, you are documenting the delivery surface and missing the operator.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.