A sophisticated PAYLOAD ransomware attack targeted a manufacturing organization in the Middle East, exploiting vulnerabilities in Microsoft Active Directory Group Policy. The attackers gained initial access on April 11 by compromising a domain account through the company's FortiGate SSL VPN. By April 13, they escalated privileges to a domain administrator and created a malicious Group Policy Object (GPO) named “PAYLOAD,” which was linked at the root of the domain. This GPO allowed them to distribute a ransom note, change desktop images, display a ransom message during login, and disable the local administrator account. A secondary GPO, “win Firewall Off,” was used to disable Windows Firewall across all profiles. The malicious changes activated on April 14 after system reboots, causing widespread disruption. The attackers also exfiltrated sensitive data, which was later released on the dark web. Kaspersky's investigation found no evidence of file encryption or active malware processes, indicating the attack was contained within Active Directory. Recommendations for organizations include monitoring GPO modifications, implementing multi-factor authentication for VPN access, and safeguarding privileged accounts.