ISLAMABAD, Tuesday, September 22, 2026: Cybersecurity firm Kaspersky has uncovered a stealthy ransomware tactic capable of disrupting entire corporate networks, locking users out of systems and displaying ransom demands without encrypting files or installing a conventional ransomware program.
The attack, involving the Payload ransomware family, was identified by Kaspersky’s Global Emergency Response Team (GERT) while responding to a security incident at a manufacturing company in the Middle East.
Kaspersky researchers said the incident points to a growing shift towards “encryptionless extortion,” in which cybercriminals steal sensitive information and disrupt business operations instead of relying solely on file encryption to pressure victims into paying ransom.
In the investigated attack, the threat actors obtained highly privileged administrator access to the company’s Active Directory environment. Kaspersky said the credentials were likely acquired through phishing before being used to access the corporate network through legitimate remote-access and VPN channels.
Because the attackers were operating with privileged credentials, their activity could resemble that of legitimate IT administrators, making the intrusion harder to detect.
Rather than deploying conventional ransomware across Windows computers, the attackers exploited the organisation’s own administrative infrastructure.
They created a malicious Group Policy Object (GPO) named “PAYLOAD” and linked it to the root of the corporate domain. Group Policy is normally used by administrators to centrally configure computers across an organisation.
Once activated, the malicious policy disabled local administrator accounts, distributed ransom notes and replaced desktop wallpapers and lock screens with ransom messages across domain-connected Windows workstations.
Kaspersky’s technical investigation found that no files were encrypted on the affected Windows machines and no malicious ransomware binary was installed on those endpoints. The company said a Payload sample targeting ESXi was found on Linux servers.
The attackers also exfiltrated corporate data from file servers and other systems. The stolen information was subsequently published on the dark web as part of the extortion attempt.
Kaspersky said the technique demonstrates how attackers with control of central network infrastructure can cause organisation-wide disruption while potentially evading security systems focused primarily on detecting malicious files and processes.
“The tactics behind PAYLOAD represent another development in cybercriminal tactics,” Kaspersky GERT security expert Elsayed Elrefaei said.
He warned that conventional endpoint malware scanning alone may be insufficient when attackers compromise central network policies, calling on organisations to secure privileged credentials and focus more closely on detecting suspicious behaviour.
The incident also reflects a wider ransomware trend identified in Kaspersky’s State of Ransomware 2026 report, which found that some cybercriminal groups are increasingly turning to extortion models centred on data theft, operational disruption and threats to leak sensitive information rather than traditional encryption-based attacks.
To reduce exposure to similar attacks, Kaspersky advised organisations to closely monitor the creation and modification of Group Policy Objects and configure alerts whenever new policies are linked to the root of a corporate network.
It also recommended phishing-resistant multi-factor authentication for administrative systems and VPN access, tighter controls over highly privileged accounts and limiting Domain Admin credentials to dedicated and isolated systems.
The findings underline an evolving cybersecurity challenge for businesses: ransomware attacks may no longer require criminals to encrypt thousands of files to cause serious disruption. Gaining control of trusted administrative infrastructure can itself provide attackers with significant leverage over an organisation.
