PAYLOAD Ransomware Emerges as a Fast-Growing Extortion Threat
PAYLOAD ransomware surfaced in February 2026 and quickly listed around 50 victims on its Tor leak site, abusing FortiGate SSL VPN logins and malicious Group Policy Objects to extort organizations with or without encryption.
TA2026282Published September 25, 2026Admiralty A1TA2026282A150 by late March 2026.payloadSummary
PAYLOAD is a ransomware and data extortion operation that surfaced in February 2026 and quickly listed around 50 victims on its Tor leak site. In an intrusion against a Middle Eastern manufacturer, PAYLOAD operators holding domain admin rights skipped the encryptor altogether, abused a FortiGate SSL VPN login with stolen credentials, and pushed malicious Group Policy Objects domain-wide to drop ransom notes, deface screens, disable the firewall, and lock out local administrators, while stealing data from file servers for publication.
Malware
Targeted Products
Targeted Regions (39)
Argentina, Austria, Bahrain, Brazil, Canada, China, Colombia, Dominican Republic, Egypt, France, Germany, Greece, India, Ireland, Israel, Italy, Jamaica, Japan, Jordan, Malaysia, Mexico, Paraguay, Philippines, Poland, Puerto Rico, Qatar, Singapore, South Africa, Spain, Sri Lanka, Switzerland, Taiwan, Thailand, Turkey, United Arab Emirates, United Kingdom, United States, Venezuela, Vietnam
Targeted Industries (25)
Agriculture, Aviation, Business Services & Consulting, Construction, E-Commerce, Education, Energy, Engineering, Financial Services, Food & Beverage, Government, Healthcare, Hospitality, Insurance, Legal, Logistics, Manufacturing, Media, Professional Services, Real Estate, Retail, Technology, Telecommunications, Transportation, Utilities
Attack Details
- #01
PAYLOAD is a ransomware and data extortion group that first appeared on
February 15, 2026. By late March 2026, it had posted about50victims on its leak site. Most were in Egypt and the wider Middle East and North Africa region, with others in Mexico, Poland, and elsewhere. Victims span the logistics, transportation, real estate, construction, manufacturing, professional services, and technology sectors. - #02
In April 2026, the PAYLOAD group breached a manufacturing company in the Middle East by logging into its FortiGate SSL VPN with a stolen employee account. It is unclear how the attackers obtained the password; it may have come from password guessing, phishing, or a purchase on criminal markets.
- #03
With administrator rights over the whole domain, the attackers used Group Policy, the built-in Windows tool for managing settings across a company's computers, to push malicious changes to every connected system at once. These changes dropped ransom notes, displayed a ransom message at login, replaced desktop and lock screen images, turned off the Windows Firewall, and disabled the local administrator account. The changes took effect the next day, when most computers restarted. Because the settings reapplied on every restart, they stayed in place without any malware on the machines. No files were encrypted in this attack. Instead, the attackers stole data from file servers and other systems and later published it online.
- #04
When the group deploys its PAYLOAD Windows ransomware, the program first stops dozens of applications and services, including databases, Office programs, email clients, backup tools, and security software, so that files are unlocked for encryption and are harder to recover. It deletes Windows backup snapshots, hides its activity from security monitoring, and can spread to shared network drives, allowing a single infected machine to affect files across the network.
- #05
The ransomware locks each file with a unique encryption key, so files cannot be recovered without the attackers' key, and adds the
.payloadextension to each file name. It then leaves a ransom note, wipes Windows event logs to hide its tracks, and can delete itself. The note gives victims72hours to make contact and threatens to publish stolen data after10days. Whether or not files are encrypted, stealing data and threatening to leak it is how the PAYLOAD group pressures victims to pay.
Recommendations
- 01Remove Malicious PAYLOAD and Firewall GPOs
Search Group Policy for objects named "PAYLOAD" or "win Firewall Off", or matching the GUIDs listed in this advisory, delete them from domain controllers, and remove their links from the domain root and any OUs.
- 02Clean SYSVOL of Staged Artifacts
Inspect SYSVOL for unexpected files such as
payload.jpgandhello.txt, remove them, and confirm that replication has cleared them from every domain controller. - 03Restore Endpoint Security Settings
Force a Group Policy refresh after removing the malicious GPOs, re-enable Windows Firewall on all profiles, restore the legitimate state of the local Administrator account, and reset legal notice, wallpaper, and lock screen settings.
- 04Reset Compromised and Privileged Credentials
Reset the credential used for VPN access along with all domain admin and GPO-capable accounts, and reset the KRBTGT password twice if broader domain compromise is suspected.
- 05Audit Directory Service Changes
Enable auditing for Event IDs
5136,5137, and5141, and alert on new GPO creation and gPLink changes, especially links at the domain root outside approved change windows. - 06Separate GPO Creation from Linking Rights
Restrict who can create GPOs and who can link them, and require change approval for any policy linked at the domain level.
- 07Harden ESXi Hosts
Restrict ESXi management access to dedicated admin networks, monitor for changes to hypervisor security policies, and keep hosts at supported, patched versions.
- 08Protect Backups from Tampering
Keep offline or immutable backups isolated from domain credentials, and regularly test restores so recovery does not depend on shadow copies or reachable backup services.
Indicators of Compromise (IoCs)
| Type | Value |
|---|---|
SHA256 | 1CA67AF90400EE6CBBD42175293274A0F5DC05315096CB2E214E4BFE12FFB71F |
SHA1 | DDE1B933AAD33C5D96C2E45AD46434A200DC46A6 |
MD5 | E0FD8FF6D39E4C11BDAF860C35FD8DC0 |
IPv4 | 37[.]19[.]210[.]12 |
Filename | killer.exe |
Mutex | MakeAmericaGreatAgain |
TOR Address | payloadrz5yw227brtbvdqpnlhq3rdcdekdnn3rgucbcdeawq2v6vuyd[.]onion |
Registry Key | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\legalnoticecaption |
GPO GUID | {C897F2C7-C2AC-4E6F-BF48-58036FF29E79} |
File Extension | .payload |
MITRE ATT&CK TTPs
T1078T1133T1078T1078.002T1484T1484.001T1686T1562T1562.006T1070T1070.001T1070.004T1027T1027.013T1480T1480.002T1059T1059.003T1106T1083T1135T1005T1071T1486T1490T1489T1491T1491.001T1531References & Patch Links
Recent Breaches (73)
https://qualiflex-solutions.chhttps://zaraholding.comhttps://stuecheli.chhttps://baya-tech.comhttps://bb-hydraulik.dehttps://kronenberg-gmbh.dehttps://ckr.co.zahttps://roofinox.comhttps://castries.frhttps://velafilmsrl.comhttps://tofutown.comhttps://www.mosaic-partners.comhttps://clinicalasabana.comhttps://softwarearge.comhttps://qualiflex.chhttps://vitale.com.brhttps://preferred-properties.orghttps://www.myenb.chhttps://sporton.com.twhttps://myipo.gov.myhttps://plazalama.com.dohttps://vpd.attanahotels.comhttps://hansoll.comhttps://asonic-logistics.comhttps://www.gtf-freese.dehttps://robinsons.com.sghttps://impcullman.comhttps://hs1992.jphttps://www.elohimlaw.comhttps://tangsengservices.comhttps://goreycs.iehttps://amemanufacturing.com.myhttps://ros-management.comhttps://rmgimli.comhttps://b3-bruck.athttps://meditron.com.vehttps://pstbn.com.pyhttps://caravaningcity.comhttps://betterhouse-eg.comhttps://johinvestments.comhttps://alsulaitilawfirm.comhttps://www.marino.co.inhttps://sunlightair.phhttps://www.orientalweavers.comhttps://www.tfegroup.com.hkhttps://franziskusschule-wilhelmshaven.dehttps://wastani.com.eghttps://tscherne.athttps://uf-eg.comhttps://www.sayegh1944.comhttps://www.nkartravelhouse.comhttps://q2als.comhttps://aaagroup.comhttps://www.carlysle.nethttps://vancompare.comhttps://www.igls.nethttps://www.hoppecke.comhttps://tslines.comhttps://notaria89nl.comhttps://lucky-mfg.comhttps://www.royalbahrainhospital.comhttps://tylermedia.comhttps://riograndepr.nethttps://www.thaisolarenergy.comhttps://www.unitedlimsun.comhttps://www.easyservizi.comhttps://www.prizmpain.comhttps://insacor.com.arhttps://jtpackoffoods.comhttps://afdrd.comhttps://sodic.comhttps://gridff.comhttps://adfsa.com.mx
