Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO

2026-09-22T20:51:47Z•ac9e5f32f3840692ebf94355ee319246ce5cdcb860b06234a8f33de194dc7394
Active-DirectoryElementGPO-abuseGhostContainerGroup-Policy-ObjectsHiveMQICS-security vulnerabilities-and-exploits AI-security Android-**MQTTMatrixMirage-KittenMovieReaperNightEagleNodeRabbitPAYLOAD-ransomwarePollCatRDPSolanaToy-GhoulsValleyRATbinaryless-attackblockchain-C2industrial-control-systemsransomwarethreat-intelligencetorrent-malware

What happened

Kaspersky Securelist threat intelligence covering September–August 2026 activity, including ransomware abuse of Active Directory Group Policy, torrent-delivered malware using blockchain-based C2 concealment, APT campaigns targeting Russian, Middle Eastern, African, aviation, financial, and industrial sectors, novel backdoors and rootkits, Android proxy botnets, and vulnerability and exploit trends. The collection highlights enterprise compromise through AD, RDP, GPO, kernel-level concealment, compromised software, and abuse of legitimate cloud, messaging, MQTT, GitHub, and blockchain services.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
ac9e5f32f3840692ebf94355ee319246ce5cdcb860b06234a8f33de194dc7394
Enrichment time
2026-09-22T20:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.