Summary
- Attackers with domain-level GPO rights created malicious policies that changed lock screens, delivered ransom notices, disabled local administration, and switched off Windows Firewall.
- Kaspersky found no Windows file encryption or resident ransomware binary on the affected workstations; data was nevertheless stolen and later published.
- A PAYLOAD ransomware sample targeting ESXi on Linux servers was the only conventional ransomware payload Kaspersky found in the incident.
A ransomware incident investigated by Kaspersky shows how attackers can create widespread disruption across a Windows domain without deploying a conventional file-encrypting payload to each endpoint.
Kaspersky said its Global Emergency Response Team encountered the technique while responding to an attack on a manufacturing company in the Middle East. The attackers used Active Directory Group Policy to impose disruptive changes across corporate devices, locking down systems and displaying ransom demands.
The investigators reconstructed initial access as a compromised valid account used through a FortiGate SSL VPN. Insufficient logging meant they could not establish how the credential had been obtained. Phishing, password spraying or credential stuffing, and brokered access were identified as possibilities rather than confirmed entry routes.
Once the attackers held sufficient privileges, Group Policy provided a central mechanism for disruption. The technology is designed to let administrators configure large populations of Windows systems consistently across a domain. The same capability can be abused by an attacker with domain-level control.
Kaspersky found two malicious policies linked at the domain root. The changes included altering lock-screen content, delivering ransom notices, restricting local administrative access, and disabling Windows Firewall. Those settings could be propagated widely without dropping a conventional ransomware executable on each workstation.
No Windows file encryption was observed on the affected workstations, and Kaspersky said it did not find a resident Windows ransomware binary responsible for the disruption. Data was nevertheless stolen during the intrusion and was later published by the attackers.
The wider environment was not entirely free of encryption. Investigators identified a PAYLOAD ransomware sample targeting VMware ESXi systems on Linux infrastructure, making it the only conventional ransomware payload Kaspersky found in the case.
That combination matters because it separates extortion from the familiar endpoint-encryption model. A victim can experience broad operational disruption, stolen data, ransom pressure, and selective encryption even when Windows workstations themselves are not encrypted.
The technique also changes some detection assumptions. Endpoint controls commonly look for bulk file modification, suspicious encryption routines, deletion of backups, or known ransomware binaries. Group Policy abuse can instead use legitimate administrative mechanisms after privileged identities have already been compromised.
The security problem therefore moves upstream. Unusual Group Policy changes, privileged authentication, directory modifications, VPN access patterns, and activity around virtualisation infrastructure may reveal the attack before the final disruptive policies are applied.
Active Directory remains especially consequential because of that concentration of control. Domain-level access can influence authentication, configuration, software deployment, policy, and large populations of endpoints. Once attackers obtain that authority, operational effects no longer depend on installing malware machine by machine.
The case also fits a broader separation between ransomware and encryption. Extortion groups increasingly combine data theft, service disruption, publication threats, and pressure on customers or partners. Encryption remains common, but it is one coercive tool rather than a defining requirement of every ransomware operation.
A single incident does not establish how widespread this model has become, and Kaspersky’s findings concern one investigated environment. It does, however, show that defenders cannot assume the absence of mass Windows encryption means the organisation has avoided a ransomware-style disruption.
Recovery in such a case also looks different. Restoring encrypted workstation files may not be the central task, but organisations still have to regain confidence in Active Directory, privileged credentials, policy objects, VPN access, and the wider management plane before returning systems to normal operation.




