Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO
2026-09-23T20:51:45Z•9d046f3f9c4c50abfc94685d4584f22f3ed399ded2b35bf8aa6975eea165f5bf
APTActive DirectoryAndroid malwareGitHubGroup PolicyICSMQTTRDPbackdoorblockchain C2exploitindustrial control systemsmalwareproxy botnetransomwarerootkitthreat-intelligencetorrent malwarevulnerabilities
What happened
Kaspersky Securelist feed containing recent threat intelligence on ransomware abusing Active Directory Group Policy, torrent-delivered malware using blockchain-based C2 concealment, APT campaigns, backdoors, rootkits, industrial control system threats, Android proxy botnets, and vulnerability trends during Q2 2026.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 9d046f3f9c4c50abfc94685d4584f22f3ed399ded2b35bf8aa6975eea165f5bf
- Enrichment time
- 2026-09-23T20:51:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.