
Findings and evidence
Kaspersky GERT reports an April manufacturing-sector incident in which Group Policy changes disrupted Windows workstations and displayed ransom demands without encrypting their files. The investigators separately identified an ESXi ransomware sample and data theft.
Why it matters
The case broadens the evidence set beyond a ransomware executable. Preserve directory audit records, policy history and administrative changes, then correlate them with endpoint and file-server activity. Recovery planning needs to account for changes in the management plane.
Scope and limits
The absence of Windows file encryption applies to this investigated incident. It does not establish that every PAYLOAD deployment behaves the same way.
Primary source
Kaspersky / Securelist: original publication. Source published 2026-09-21. Brief prepared by websec.gr on 26 September 2026. This is an editorial research summary, not a claim of independent replication.