◈ Cii.中国 · 天地一体信息中心 九霄观澜 · 宇宙观察 · RSS

Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO

暗流情报2026-09-21 · 来源:cii·Securelist 卡巴斯基
Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO

Kaspersky GERT experts dive into the technical incident analysis of PAYLOAD ransomware: an encryptionless, binary-less operation that abused Active Directory mechanisms for managing Group Policy Objec

原文标题:Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO

溯源:cii·深网监测 | 可信度:B(中高(公开深网/暗网威胁情报))

信源:Securelist 卡巴斯基 | 阅读原文

Kaspersky GERT experts dive into the technical incident analysis of PAYLOAD ransomware: an encryptionless, binary-less operation that abused Active Directory mechanisms for managing Group Policy Objects.

—— cii·深网监测 · 网 · 可信度B