More than a year ago, we discussed how to detect attacks based on group policy compromise and how to organize proactive GPO monitoring in SOC. Perhaps such things are better remembered through practical examples.
And here comes a real case. In April 2026, our experts investigated a security incident at a manufacturing organization in the Middle East. The threat actor obtained domain admin-equivalent control of the organization’s Active Directory environment and authored a malicious Group Policy Object (GPO) named PAYLOAD, linking it at the domain root.
Through that single object, the actor delivered ransom notes, hijacked the desktop wallpaper and lock screen, enforced a logon banner, and disabled the local administrator account across every domain-joined Windows workstation. The data stolen from the organization’s servers was later published on the Darkweb.
Thus, using only GPOs, the attacker was able to disrupt the operations of the entire domain without deploying malicious executable files on endpoints — and cause damage to the organization.
How to defend:
Detection strategies based solely on file- or process-based indicators are blind to this attack class, since no malware was used. In short, effective GPO protection should include:
— directory service change auditing,
— SYSVOL integrity monitoring,
— analyzing policy application telemetry on endpoints.
For more detailed guidance on detecting such attacks, check the article by Ahmad Zaidi Said and Elsayed Elrefaei “Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO”.
