Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO
2026-09-23T08:51:48Z•72caf50d90c6d1f2dac80b5107db3b6525c125c5d9e830cb7645c402014ec26c
APTActive DirectoryAndroid malwareElement MessengerFinTechGPO hijackingGitHub-hosted toolsGroup Policy ObjectsICSMQTTRDP exploitationSolana blockchainaviationbackdoorbinaryless malwarecommand-and-controlindustrial control systemskernel-mode rootkitmalvertisingproxy botnetransomwarerootkitsupply-chain compromisetorrent malspamvulnerability exploitation
What happened
Kaspersky Securelist reporting from August–September 2026 covers ransomware abuse of Active Directory Group Policy, torrent-delivered multi-stage malware using Solana for C2 concealment, APT campaigns targeting Russian, Middle Eastern, African, aviation, and financial organizations, MQTT/Element-based backdoors, adware masquerading, industrial control system threats, Android proxy botnets, and a kernel-level Windows rootkit. The collection highlights active exploitation of enterprise infrastructure, covert command-and-control, persistence, defense evasion, and malware delivery through trusted-
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 72caf50d90c6d1f2dac80b5107db3b6525c125c5d9e830cb7645c402014ec26c
- Enrichment time
- 2026-09-23T08:51:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.