PAYLOAD ransomware hijacks Windows Group Policy in encryption-less attacks
Brief
A PAYLOAD ransomware incident weaponized Microsoft Active Directory Group Policy to disrupt an organization’s Windows computers without deploying ransomware or encrypting files. Instead, the attackers used the company’s own administration infrastructure to display ransom notes, change wallpapers, deactivate local administrator accounts, and turn off Windows Firewall across the network.
Kaspersky’s Global Emergency Response Team (GERT) …
The post PAYLOAD ransomware hijacks Windows Group Policy in encryption-less attacks appeared first on CyberInsider .
