Site icon techcoffeehouse.com

Kaspersky Uncovers Encryptionless Ransomware Tactic ‘Payload’

One Identity Offers Free Security Risk Assessment to SolarWinds Customers and Free Safeguard for Proactive Privilege Defense
Advertisements

Kaspersky‘s Global Emergency Response Team has uncovered a new ransomware tactic that locks up corporate networks and extorts victims without encrypting a single file. The tactic, which the attackers named “Payload”, was found during an incident response at a manufacturing company in the Middle East.

Instead of deploying a conventional encryptor, the attackers took over the company’s network entirely — locking computers, displaying ransom notes and changing desktop wallpapers across the organisation, all without a traditional malware payload doing the damage.

A shift toward encryptionless extortion

Kaspersky says the incident reflects a trend flagged in its State of Ransomware 2026 report: criminals are moving away from file encryption and toward disrupting operations directly, then leaking stolen data on the dark web to pressure victims into paying.

The attackers gained access by acquiring administrator credentials, likely through phishing, and logged into the network through standard remote-access and VPN channels — appearing to security teams as legitimate IT staff carrying out routine work. From there, they created a malicious Group Policy Object named “PAYLOAD” inside the company’s Active Directory, using a legitimate and highly privileged administrative tool to disable local administrator accounts and push ransom notes to every machine at once.

“The tactics behind PAYLOAD represent another development in cybercriminal tactics. When attackers hijack central network rules, traditional endpoint malware scanning alone may be insufficient while the malicious Group Policy remains active. Organisations must prioritise blocking the malicious policies at the source, strictly locking down administrative credentials, and shifting their defence to monitoring behaviour rather than just scanning for malware,” said Elsayed Elrefaei, a security expert at Kaspersky’s Global Emergency Response Team.

What Kaspersky recommends

Kaspersky is advising organisations to monitor all Group Policy Object creations and changes closely, with alerts triggered the moment a new rule is linked to the root of the network. It also recommends phishing-resistant multi-factor authentication, such as physical security keys, for administrative and VPN access, and stricter limits on which accounts can reach every workstation and server at once.

The full technical breakdown of the Payload tactic is available on Kaspersky’s Securelist research blog.

Author

Exit mobile version