LiMP VPN
All news

Payload Attack: Kaspersky Reveals Ransomware Without Encryption

Payload Attack: Kaspersky Reveals Ransomware Without Encryption

In short: Kaspersky's Global Information Response Team (GIRT) disclosed the Payload attack against a manufacturing company: criminals seized Active Directory via compromised admin credentials, deployed a malicious Group Policy Object (GPO), and locked the entire enterprise — without encrypting a single file. Data had been exfiltrated in advance and threatened for release on a darknet leak site as leverage.

Ransomware without the ransomware: what happened

In September 2026, Kaspersky's GIRT team, led by Konstantin Sapronov, published technical details of an unusual attack on a manufacturing company in the Middle East. The attackers achieved full disruption and extortion without deploying any encryption software. The campaign was named Payload after the Group Policy Object (GPO) they created inside the hijacked Active Directory.

Kaspersky experts described encryption-less extortion as a "significant shift" in cybercriminal tactics observed across 2026.

How the Payload attack unfolded: step by step

According to Kaspersky's technical report, the attack followed five stages:

  1. Credential acquisition. The attackers obtained compromised admin credentials with elevated privileges — likely via phishing, brute force, or initial-access brokers on underground markets.
  2. Silent entry. They connected through standard remote-access tools and the company's own VPN gateway, appearing identical to legitimate IT operations on monitoring dashboards.
  3. Active Directory takeover. With domain controller access secured, the group gained full control of the enterprise network infrastructure.
  4. The Payload GPO. A Group Policy Object named Payload was created inside the hijacked AD. It pushed ransom demand wallpapers and lock screens to all corporate machines and simultaneously disabled all administrative accounts enterprise-wide.
  5. Pre-staged data theft. Before triggering the lockout, the attackers exfiltrated corporate data and posted samples on a darknet leak site as proof and leverage.

The result: an entire enterprise locked out of its own infrastructure, employees facing ransom demands on every screen, and corporate data in criminal hands — with zero files encrypted.

Why this is more dangerous than classic ransomware

Traditional endpoint protection detects ransomware by behavioural signatures: mass file modifications, specific Windows API calls, ransom note creation. The Payload attack leaves none of these traces, because no files are touched at all.

Everything that happens uses legitimate Windows mechanisms — GPO policy propagation and account management — which look like routine administrative work to most security monitoring systems. This is what the industry calls living-off-the-land (LotL) — using built-in system tools as weapons. There is nothing anomalous to flag until the GPO fires and the lockout becomes visible to every employee simultaneously.

Encryption-less attacks also reduce operational risk for criminals: deploying ransomware leaves detectable artefacts and is often caught at early stages. Seizing AD through a legitimate remote-access channel and standard management tools is far quieter and harder to detect.

The 2026 trend: extortion without encryption is growing

Payload is not isolated. Kaspersky's 2026 International Anti-Ransomware Day findings documented the emergence of The Gentlemen — a new group formed from ex-RaaS affiliates specialising in data-centric extortion without encryption. Similar tactics are used by Clop (mass-emailing ransom demands from hijacked corporate accounts, zero file encryption) and The Pink threat group (immediate SharePoint and OneDrive exfiltration followed by a darknet leak site launch).

The threat vector is shifting: while classic ransomware holds data hostage through encryption, the new wave holds infrastructure access and corporate reputation hostage instead.

What this means for your data security

The Payload attack illustrates how much damage compromised credentials alone can cause. The entire attack chain was only possible because the attackers obtained privileged admin passwords. Weak, reused, or previously leaked passwords are the most common entry point in attacks of this type.

Practical steps for both personal and corporate protection:

  • Credentials for corporate systems must never be stored in unencrypted channels — unencrypted email, messaging apps, or password managers without a master password.
  • Connecting to corporate infrastructure over unsecured or public networks increases the risk of credential interception. Learn more about traffic encryption on the LiMP VPN features page.
  • Two-factor authentication (2FA) on privileged accounts is mandatory: even with a stolen password, the attacker cannot log in without the second factor.
  • Monitoring Active Directory changes and Group Policy modifications is essential for every IT team — that monitoring would have flagged the Payload attack at an early stage.

More on protecting accounts from credential compromise in the LiMP VPN security blog.

Sources