Kaspersky analyzes PAYLOAD ransomware and Active Directory abuse
Kaspersky GERT experts have analyzed a PAYLOAD ransomware attack that exploits Active Directory Group Policy Objects.

Experts from Kaspersky's GERT team have conducted an in-depth technical analysis of a cyber incident linked to the PAYLOAD ransomware.
The operation stood out for being fileless and without data encryption. The attackers directly abused the Active Directory mechanisms used for managing Group Policy Objects (GPOs), exploiting these group policies as a tool to deliver the attack.
