{"id":5571,"date":"2026-09-22T14:39:25","date_gmt":"2026-09-22T09:39:25","guid":{"rendered":"https:\/\/pcn58.com.pk\/?p=5571"},"modified":"2026-09-22T14:39:25","modified_gmt":"2026-09-22T09:39:25","slug":"kaspersky-uncovers-stealthy-payload-ransomware-campaign-targeting-corporate-networks","status":"publish","type":"post","link":"https:\/\/pcn58.com.pk\/index.php\/2026\/09\/22\/kaspersky-uncovers-stealthy-payload-ransomware-campaign-targeting-corporate-networks\/","title":{"rendered":"Kaspersky uncovers stealthy \u2018Payload\u2019 ransomware campaign targeting corporate networks"},"content":{"rendered":"\n<p>Islamabad : Kaspersky\u2019s Global Emergency Response Team (GERT) has published a new report analyzing a sophisticated new tactic in the Payload ransomware family. Discovered during an incident response at a manufacturing company in the Middle East, this attack demonstrates a major shift in cybercrime: the attackers took complete control of the company&#8217;s network and forced its computers to lock up, display ransom notes, and change desktop wallpapers \u2013 all without deploying a conventional ransomware encryptor.<\/p>\n\n\n\n<p>This incident illustrates one of the trends mentioned in Kaspersky\u2019s State of Ransomware 2026 report released earlier this year: attackers are increasingly moving away from traditional file encryption. Instead, they are adopting \u201cencryptionless extortion\u201d &#8211; focusing on immediate operational disruption and leaking sensitive, stolen data on the dark web rather than relying on cryptographic keys to squeeze payments out of victims.<\/p>\n\n\n\n<p>Rather than using complex malware viruses to break into the network, the attackers bypassed initial defenses by acquiring administrator rights. Likely via phishing, they obtained highly privileged user credentials, which they then used to log directly into the corporate network through standard remote-access and VPN entry points. All of this went undetected, with the attackers appearing to security monitors as legitimate IT staff logging in for routine tasks.<\/p>\n\n\n\n<p>The intruders used the company\u2019s own trusted administrative tools to further execute their attack. They targeted the company\u2019s Active Directory (the backbone of a corporate network) and created a malicious Group Policy Object (GPO) rule.<\/p>\n\n\n\n<p>GPOs are used by network administrators to instantly configure settings across thousands of employee computers. Because Group Policy is a legitimate and highly privileged administrative mechanism, malicious changes performed using compromised privileged accounts can resemble legitimate IT activity. By executing the entire attack inside a malicious GPO rule which they named &#8220;PAYLOAD,&#8221; the hackers operated in complete silence. The rule instantly disabled local administrator accounts, pushed out ransom notes, and hijacked every computer&#8217;s desktop wallpaper and lock screen to display a ransom graphic the moment the systems processed the updated policies.<\/p>\n\n\n\n<p>The attackers focused their efforts on exfiltrating valuable corporate assets. Once the theft was complete and the administrative lockouts were triggered, the exfiltrated data was ultimately published on the dark web to finalize the extortion attempt.<\/p>\n\n\n\n<p>&#8220;The tactics behind PAYLOAD represent another development in cybercriminal tactics. When attackers hijack central network rules, traditional endpoint malware scanning alone may be insufficient while the malicious Group Policy remains active. Organizations must prioritize blocking the malicious policies at the source, strictly locking down administrative credentials, and shifting their defense to monitoring behavior rather than just scanning for malware,\u201d comments Elsayed Elrefaei, a security expert at Kaspersky Global Emergency Response Team.<\/p>\n\n\n\n<p>Kaspersky recommends that the network administrators should closely monitor all GPO creations and modifications. Security alerts should be configured to trigger the moment a new rule is linked to the root of the corporate network. Ensure that any access to the network&#8217;s administrative systems and VPN entry points requires highly secure, phishing-resistant multi-factor authentication (for instance, physical security keys). Enforce strict administrative boundaries. General IT administrators should not have &#8220;master keys&#8221; that can access every workstation and server simultaneously. Limit highly privileged &#8220;Domain Admin&#8221; accounts strictly to dedicated, isolated systems.<\/p>\n\n\n\n<p>The full report is available on Securelist.com.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Islamabad : Kaspersky\u2019s Global Emergency Response Team (GERT) has published a new report analyzing a sophisticated new tactic in the Payload ransomware family. Discovered during an incident response at a &hellip; <a href=\"https:\/\/pcn58.com.pk\/index.php\/2026\/09\/22\/kaspersky-uncovers-stealthy-payload-ransomware-campaign-targeting-corporate-networks\/\" class=\"more-link\">Read More<\/a><\/p>\n","protected":false},"author":1,"featured_media":5572,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"footnotes":""},"categories":[12],"tags":[132],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/pcn58.com.pk\/index.php\/wp-json\/wp\/v2\/posts\/5571"}],"collection":[{"href":"https:\/\/pcn58.com.pk\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pcn58.com.pk\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pcn58.com.pk\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pcn58.com.pk\/index.php\/wp-json\/wp\/v2\/comments?post=5571"}],"version-history":[{"count":1,"href":"https:\/\/pcn58.com.pk\/index.php\/wp-json\/wp\/v2\/posts\/5571\/revisions"}],"predecessor-version":[{"id":5573,"href":"https:\/\/pcn58.com.pk\/index.php\/wp-json\/wp\/v2\/posts\/5571\/revisions\/5573"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/pcn58.com.pk\/index.php\/wp-json\/wp\/v2\/media\/5572"}],"wp:attachment":[{"href":"https:\/\/pcn58.com.pk\/index.php\/wp-json\/wp\/v2\/media?parent=5571"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pcn58.com.pk\/index.php\/wp-json\/wp\/v2\/categories?post=5571"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pcn58.com.pk\/index.php\/wp-json\/wp\/v2\/tags?post=5571"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}