Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO

2026-09-22T08:51:46Z•0ad5cf3ada4e929c7e290c2dcb29f3e2baeddf3c31b17a38302c6698bf5b4f2f
AI frameworks securityActive DirectoryC2 concealmentElement messengerGPO abuseGhostContainerGroup Policy ObjectsICSMQTT C2Mirage KittenMovieReaperNightEagleNodeRabbitPollCatRDP exploitationSolana blockchainToy GhoulsValleyRATadware masqueradingbinaryless attackexploitsindustrial control systemsransomwaretorrent malwarevulnerabilities

What happened

Kaspersky Securelist threat intelligence covering September–August 2026 activity, including ransomware abuse of Active Directory Group Policy, torrent-delivered malware using blockchain-based C2 concealment, APT campaigns, novel backdoors, kernel-level rootkits, Android proxy botnets, industrial control system threats, and vulnerability/exploit trends.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
0ad5cf3ada4e929c7e290c2dcb29f3e2baeddf3c31b17a38302c6698bf5b4f2f
Enrichment time
2026-09-22T08:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.