Payload Ransomware and New Cyber Attack Methods

Serdar HocamAuthor & Editor

GERT researchers have reported on a new Payload ransomware family, which does not feature traditional file encryption and was detected at a manufacturing company based in the Middle East.

◉ 3 views
Payload fidye yazılımı ortaya çıktı - Bilim Teknoloji Haberleri

GERT, operating in the field of cybersecurity, examined the newly detected Payload ransomware family in a detailed report during an incident response targeting a manufacturing company in the Middle East.

Discovery of Payload Ransomware

A new report prepared by GERT discussed the Payload ransomware family detected during an incident response targeting a manufacturing company in the Middle East. This new development highlights tactical shifts in the world of cybercrime.

An Attack Tactic Outside the Traditional Approach

Instead of using a traditional ransomware encryptor, the attackers achieved full control over the corporate network using different methods. Steps such as locking computers, displaying ransom notes, and changing desktop wallpapers were taken.

Seizure of Administrator Privileges

To infiltrate the network, the attackers obtained high-privileged credentials via phishing and seized administrator privileges. A malicious Group Policy Object rule was created on Active Directory.

Data Leakage and Operational Disruptions

Local administrator accounts were disabled under the name PAYLOAD, and ransom notes were distributed while data was leaked on the dark web. This situation indicates that the attacks focused directly on operational disruptions.