PAYLOAD Ransomware Emerges as a Fast-Growing Extortion Threat

Red | Attack
PAYLOAD Ransomware Emerges as a Fast-Growing Extortion Threat | HiveForce Labs Threat Advisory
HiveForce Labs · Threat Advisory · Attack Report

PAYLOAD Ransomware Emerges as a Fast-Growing Extortion Threat

PAYLOAD ransomware surfaced in February 2026 and quickly listed around 50 victims on its Tor leak site, abusing FortiGate SSL VPN logins and malicious Group Policy Objects to extort organizations with or without encryption.

Threat Level: RedAttack ReportTA2026282Published September 25, 2026Admiralty A1
TA Number
TA2026282
Published
September 25, 2026
Admiralty Code
A1
Threat Level
Red
Report Type
Attack Report
First Seen
February 15, 2026
Malware
PAYLOAD ransomware
Victims Listed
~50 by late March 2026
File Extension
.payload

01 / Overview

Summary

PAYLOAD is a ransomware and data extortion operation that surfaced in February 2026 and quickly listed around 50 victims on its Tor leak site. In an intrusion against a Middle Eastern manufacturer, PAYLOAD operators holding domain admin rights skipped the encryptor altogether, abused a FortiGate SSL VPN login with stolen credentials, and pushed malicious Group Policy Objects domain-wide to drop ransom notes, deface screens, disable the firewall, and lock out local administrators, while stealing data from file servers for publication.

Malware
PAYLOAD ransomware
Targeted Products
Microsoft Active Directory (Group Policy)Fortinet FortiGate SSL VPNVMware ESXi
Targeted Regions (39)

Argentina, Austria, Bahrain, Brazil, Canada, China, Colombia, Dominican Republic, Egypt, France, Germany, Greece, India, Ireland, Israel, Italy, Jamaica, Japan, Jordan, Malaysia, Mexico, Paraguay, Philippines, Poland, Puerto Rico, Qatar, Singapore, South Africa, Spain, Sri Lanka, Switzerland, Taiwan, Thailand, Turkey, United Arab Emirates, United Kingdom, United States, Venezuela, Vietnam

Targeted Industries (25)

Agriculture, Aviation, Business Services & Consulting, Construction, E-Commerce, Education, Energy, Engineering, Financial Services, Food & Beverage, Government, Healthcare, Hospitality, Insurance, Legal, Logistics, Manufacturing, Media, Professional Services, Real Estate, Retail, Technology, Telecommunications, Transportation, Utilities


02 / Campaign Analysis

Attack Details

  1. #01

    PAYLOAD is a ransomware and data extortion group that first appeared on February 15, 2026. By late March 2026, it had posted about 50 victims on its leak site. Most were in Egypt and the wider Middle East and North Africa region, with others in Mexico, Poland, and elsewhere. Victims span the logistics, transportation, real estate, construction, manufacturing, professional services, and technology sectors.

  2. #02

    In April 2026, the PAYLOAD group breached a manufacturing company in the Middle East by logging into its FortiGate SSL VPN with a stolen employee account. It is unclear how the attackers obtained the password; it may have come from password guessing, phishing, or a purchase on criminal markets.

  3. #03

    With administrator rights over the whole domain, the attackers used Group Policy, the built-in Windows tool for managing settings across a company's computers, to push malicious changes to every connected system at once. These changes dropped ransom notes, displayed a ransom message at login, replaced desktop and lock screen images, turned off the Windows Firewall, and disabled the local administrator account. The changes took effect the next day, when most computers restarted. Because the settings reapplied on every restart, they stayed in place without any malware on the machines. No files were encrypted in this attack. Instead, the attackers stole data from file servers and other systems and later published it online.

  4. #04

    When the group deploys its PAYLOAD Windows ransomware, the program first stops dozens of applications and services, including databases, Office programs, email clients, backup tools, and security software, so that files are unlocked for encryption and are harder to recover. It deletes Windows backup snapshots, hides its activity from security monitoring, and can spread to shared network drives, allowing a single infected machine to affect files across the network.

  5. #05

    The ransomware locks each file with a unique encryption key, so files cannot be recovered without the attackers' key, and adds the .payload extension to each file name. It then leaves a ransom note, wipes Windows event logs to hide its tracks, and can delete itself. The note gives victims 72 hours to make contact and threatens to publish stolen data after 10 days. Whether or not files are encrypted, stealing data and threatening to leak it is how the PAYLOAD group pressures victims to pay.


03 / Action Plan

Recommendations

  1. 01
    Remove Malicious PAYLOAD and Firewall GPOs

    Search Group Policy for objects named "PAYLOAD" or "win Firewall Off", or matching the GUIDs listed in this advisory, delete them from domain controllers, and remove their links from the domain root and any OUs.

  2. 02
    Clean SYSVOL of Staged Artifacts

    Inspect SYSVOL for unexpected files such as payload.jpg and hello.txt, remove them, and confirm that replication has cleared them from every domain controller.

  3. 03
    Restore Endpoint Security Settings

    Force a Group Policy refresh after removing the malicious GPOs, re-enable Windows Firewall on all profiles, restore the legitimate state of the local Administrator account, and reset legal notice, wallpaper, and lock screen settings.

  4. 04
    Reset Compromised and Privileged Credentials

    Reset the credential used for VPN access along with all domain admin and GPO-capable accounts, and reset the KRBTGT password twice if broader domain compromise is suspected.

  5. 05
    Audit Directory Service Changes

    Enable auditing for Event IDs 5136, 5137, and 5141, and alert on new GPO creation and gPLink changes, especially links at the domain root outside approved change windows.

  6. 06
    Separate GPO Creation from Linking Rights

    Restrict who can create GPOs and who can link them, and require change approval for any policy linked at the domain level.

  7. 07
    Harden ESXi Hosts

    Restrict ESXi management access to dedicated admin networks, monitor for changes to hypervisor security policies, and keep hosts at supported, patched versions.

  8. 08
    Protect Backups from Tampering

    Keep offline or immutable backups isolated from domain credentials, and regularly test restores so recovery does not depend on shadow copies or reachable backup services.


04 / Detection

Indicators of Compromise (IoCs)

TypeValue
SHA2561CA67AF90400EE6CBBD42175293274A0F5DC05315096CB2E214E4BFE12FFB71F
SHA1DDE1B933AAD33C5D96C2E45AD46434A200DC46A6
MD5E0FD8FF6D39E4C11BDAF860C35FD8DC0
0108656A3E1ADE6CA4F21B084F5E1208
BEA5E267F24D7DA59F6821BFFDBFF293
IPv437[.]19[.]210[.]12
146[.]70[.]117[.]239
149[.]102[.]229[.]154
104[.]164[.]55[.]46
104[.]28[.]162[.]228
104[.]28[.]163[.]162
64[.]190[.]76[.]14
192[.]42[.]116[.]50
192[.]42[.]116[.]12
192[.]42[.]116[.]56
192[.]42[.]116[.]97
192[.]42[.]116[.]52
Filenamekiller.exe
kill.exe
payload.jpg
hello.txt
README-payload.txt
RECOVER_payload.txt
MutexMakeAmericaGreatAgain
TOR Addresspayloadrz5yw227brtbvdqpnlhq3rdcdekdnn3rgucbcdeawq2v6vuyd[.]onion
payload6eualw6kni6v2lqn7ovjcl76ojx25z5unsyvqo3lbqy3bo5qd[.]onion
payloadynyvabjacbun4uwhmxc7yvdzorycslzmnleguxjn7glahsvqd[.]onion
Registry KeyHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\legalnoticecaption
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\legalnoticetext
GPO GUID{C897F2C7-C2AC-4E6F-BF48-58036FF29E79}
{22099AD2-E062-4F56-B574-5099BBA4E7A6}
File Extension.payload

05 / Adversary Behaviour

MITRE ATT&CK TTPs

T1078
Initial Access
Valid Accounts
T1133
Initial Access
External Remote Services
T1078
Privilege Escalation
Valid Accounts
T1078.002
Privilege Escalation
Valid Accounts › Domain Accounts
T1484
Privilege Escalation
Domain or Tenant Policy Modification
T1484.001
Privilege Escalation
Domain or Tenant Policy Modification › Group Policy Modification
T1686
Defense Evasion
Disable or Modify System Firewall
T1562
Defense Evasion
Impair Defenses
T1562.006
Defense Evasion
Impair Defenses › Indicator Blocking
T1070
Defense Evasion
Indicator Removal
T1070.001
Defense Evasion
Indicator Removal › Clear Windows Event Logs
T1070.004
Defense Evasion
Indicator Removal › File Deletion
T1027
Defense Evasion
Obfuscated Files or Information
T1027.013
Defense Evasion
Obfuscated Files or Information › Encrypted/Encoded File
T1480
Defense Evasion
Execution Guardrails
T1480.002
Defense Evasion
Execution Guardrails › Mutual Exclusion
T1059
Execution
Command and Scripting Interpreter
T1059.003
Execution
Command and Scripting Interpreter › Windows Command Shell
T1106
Execution
Native API
T1083
Discovery
File and Directory Discovery
T1135
Discovery
Network Share Discovery
T1005
Collection
Data from Local System
T1071
Command and Control
Application Layer Protocol
T1486
Impact
Data Encrypted for Impact
T1490
Impact
Inhibit System Recovery
T1489
Impact
Service Stop
T1491
Impact
Defacement
T1491.001
Impact
Defacement › Internal Defacement
T1531
Impact
Account Access Removal

06 / Sources

References & Patch Links

Recent Breaches (73)
References

Reduce real exposure. Not just vulnerability volume.