Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO

2026-09-24T08:51:46Z•dfcbdd3ff959de914fe0f3e01ebc39a9e26295e08eb0c17595f6e917774f71e0
APTActive DirectoryAndroid malwareC2 concealmentElement messengerGPO abuseGhostContainerGroup Policy ObjectsICSJavaScript malwareMQTTMirage KittenNightEagleNode.js malwareSolana blockchainToy GhoulsValleyRATbackdoorbinaryless attackexploitsขोर?industrial control systemsproxy botnetransomwaretorrent malwarevulnerabilities

What happened

Kaspersky Securelist feed covering recent threat intelligence, including ransomware abuse of Active Directory Group Policy, torrent-delivered malware, APT campaigns, novel backdoors, Android proxy botnets, industrial-control-system threats, vulnerability trends, and a kernel-level Windows rootkit. The collection includes both targeted espionage activity and financially motivated or opportunistic malware campaigns.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
dfcbdd3ff959de914fe0f3e01ebc39a9e26295e08eb0c17595f6e917774f71e0
Enrichment time
2026-09-24T08:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.