Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO
2026-09-22T20:51:47Z•ac9e5f32f3840692ebf94355ee319246ce5cdcb860b06234a8f33de194dc7394
Active-DirectoryElementGPO-abuseGhostContainerGroup-Policy-ObjectsHiveMQICS-security vulnerabilities-and-exploits AI-security Android-**MQTTMatrixMirage-KittenMovieReaperNightEagleNodeRabbitPAYLOAD-ransomwarePollCatRDPSolanaToy-GhoulsValleyRATbinaryless-attackblockchain-C2industrial-control-systemsransomwarethreat-intelligencetorrent-malware
What happened
Kaspersky Securelist threat intelligence covering September–August 2026 activity, including ransomware abuse of Active Directory Group Policy, torrent-delivered malware using blockchain-based C2 concealment, APT campaigns targeting Russian, Middle Eastern, African, aviation, financial, and industrial sectors, novel backdoors and rootkits, Android proxy botnets, and vulnerability and exploit trends. The collection highlights enterprise compromise through AD, RDP, GPO, kernel-level concealment, compromised software, and abuse of legitimate cloud, messaging, MQTT, GitHub, and blockchain services.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- ac9e5f32f3840692ebf94355ee319246ce5cdcb860b06234a8f33de194dc7394
- Enrichment time
- 2026-09-22T20:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.