← nejvýznamnější zprávy · všechny zprávy

Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO

Executive summary In April 2026, we at Kaspersky’s Global Emergency Response Team (GERT) responded to a security incident at a manufacturing organization in the Middle East. The threat actor obtained domain admin-equivalent control of the organization’s Active Directory environment and authored a malicious Group Policy Object (GPO) named PAYLOAD, linking it at the domain root. Through that single object, the actor delivered ransom notes, hijacked the desktop wallpaper and lock screen, enforced…

Číst originál na Securelist (Kaspersky) →

CZ · EN/orig

Microsoft Fortinet výroba a průmysl RU

tg: incident tg: rozbor tp: ransomware tp: únik dat tp: identita