Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO

2026-09-23T08:51:48Z•72caf50d90c6d1f2dac80b5107db3b6525c125c5d9e830cb7645c402014ec26c
APTActive DirectoryAndroid malwareElement MessengerFinTechGPO hijackingGitHub-hosted toolsGroup Policy ObjectsICSMQTTRDP exploitationSolana blockchainaviationbackdoorbinaryless malwarecommand-and-controlindustrial control systemskernel-mode rootkitmalvertisingproxy botnetransomwarerootkitsupply-chain compromisetorrent malspamvulnerability exploitation

What happened

Kaspersky Securelist reporting from August–September 2026 covers ransomware abuse of Active Directory Group Policy, torrent-delivered multi-stage malware using Solana for C2 concealment, APT campaigns targeting Russian, Middle Eastern, African, aviation, and financial organizations, MQTT/Element-based backdoors, adware masquerading, industrial control system threats, Android proxy botnets, and a kernel-level Windows rootkit. The collection highlights active exploitation of enterprise infrastructure, covert command-and-control, persistence, defense evasion, and malware delivery through trusted-

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
72caf50d90c6d1f2dac80b5107db3b6525c125c5d9e830cb7645c402014ec26c
Enrichment time
2026-09-23T08:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.