PAYLOAD ransomware attacks through Active Directory GPO
Reported 21 Sep 2026 by otx · Severity: medium
In April 2026, a manufacturing organization in the Middle East suffered a ransomware attack where threat actors with domain admin privileges weaponized Active Directory Group Policy Objects to achieve domain-wide impact without deploying ransomware binaries on Windows endpoints.