A sophisticated PAYLOAD ransomware attack targeted an unnamed manufacturing organization in the Middle East, exploiting vulnerabilities in Microsoft Active Directory Group Policy. The attackers accessed the network through a compromised domain account via FortiGate SSL VPN on April 11, escalated privileges to domain administrator by April 13, and created a malicious Group Policy Object (GPO) named "PAYLOAD." This GPO was linked at the root of the domain, allowing it to affect nearly all domain-joined Windows workstations. The attackers distributed ransom notes, altered desktop images, displayed ransom messages at login, and disabled local administrator accounts. A second GPO, "win Firewall Off," was deployed to disable Windows Firewall across all profiles. The malicious policies activated on April 14 after systems were rebooted, causing widespread disruption. The attackers also exfiltrated data from file servers and published it on the dark web, while Kaspersky found no evidence of Windows file encryption or active malware processes. Recommendations for organizations include monitoring GPO creation, checking for unexpected changes, implementing multi-factor authentication for VPN access, and protecting privileged accounts.