{"id":36878,"date":"2026-10-10T03:03:35","date_gmt":"2026-10-09T16:03:35","guid":{"rendered":"https:\/\/www.kaspersky.com.au\/blog\/ransomware-extortion-without-encryption\/36878\/"},"modified":"2026-10-10T03:03:35","modified_gmt":"2026-10-09T16:03:35","slug":"ransomware-extortion-without-encryption","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.au\/blog\/ransomware-extortion-without-encryption\/36878\/","title":{"rendered":"New ransomware trends: hijacking Active Directory instead of encrypting data"},"content":{"rendered":"<p>Many businesses still fear ransomware attacks. But is this threat still as relevant today? A few years ago, at the peak of ransomware\u2019s popularity, the term \u201cransomware\u201d was practically synonymous with malicious encryption of data. But in reality blocking access to information had long been little more than a symbolic gesture. In a May <a href=\"https:\/\/securelist.com\/state-of-ransomware-in-2026\/119761\/\" target=\"_blank\" rel=\"noopener\">Securelist post<\/a> on shifts in the ransomware threat landscape, our experts noted that in 2026, attackers are encrypting company data for ransom less and less frequently. Here\u2019s a striking example: while investigating an incident, Kaspersky\u2019s Global Emergency Response Team (GERT) uncovered the PAYLOAD extortion campaign, whose operators didn\u2019t even bother using ransomware. They took a different route instead.<\/p>\n<p>In this campaign, instead of using ransomware, the attackers seized control of the Active Directory environment, and created a malicious group policy object (GPO). They used it to deploy a ransom note, change wallpapers, and lock screens on workstations, and set up a banner to display at system login. Naturally, they also disabled local administrator accounts while they were at it. This move let the attackers demonstrate their presence in the compromised infrastructure and prove they\u2019d accessed confidential information\u00a0\u2014 just as effectively as encryption would have. Detailed information about this incident, along with indicators of compromise, can be found in the <a href=\"https:\/\/securelist.com\/tr\/payload-ransomware-via-group-policy\/121335\/\" target=\"_blank\" rel=\"noopener\">same Securelist post<\/a>. What interests us more, though, is the trend of abandoning encryption.<\/p>\n<h2>Why data encryption has lost relevance<\/h2>\n<p>Let\u2019s start with the fact that in a large company with thousands of infected computers, decrypting data is an extremely effort-intensive process. Restoring data from backups, which has become common practice largely thanks to mass ransomware attacks, is far easier than waiting for criminals to hand over a key, hoping it\u2019s genuine, and trusting that the ransomware itself didn\u2019t have bugs that made the data unrecoverable. As a result, cybercriminals found it harder and harder over time to actually collect a ransom for the decryption key.<\/p>\n<p>Attackers tried to adapt to this shift. Alongside encryption, they increasingly began stealing confidential data and threatening to publish it. Publishing confidential information puts a company\u2019s reputation, its security, and the safety of its business partners at risk. This is especially true if the data includes people\u2019s personal information: more than <a href=\"https:\/\/gdprlocal.com\/global-data-privacy-regulations\/\" target=\"_blank\" rel=\"noopener nofollow\">140 countries<\/a> around the world have data protection laws, so a leak puts an organization at a fairly high risk of a hefty fine. Sometimes that\u2019s far scarier than simply losing data, and no backup can help with that.<\/p>\n<p>Data exfiltration has another advantage from the attackers\u2019 perspective: it\u2019s usually much harder to detect than malware activity. File encryption, for instance, triggers a spike in disk activity that endpoint protection tools pick up fairly quickly. By contrast, data exfiltration is easy to disguise as normal traffic. This is precisely what the ShinyHunters group exploits, building its <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/shinyhunters-starts-leaking-data-stolen-in-salesforce-attacks\/\" target=\"_blank\" rel=\"noopener nofollow\">attacks<\/a> around the standard OAuth mechanism. On top of that, attackers can steal data much quicker if they don\u2019t bother with encryption, which also makes it harder to catch the threat in time.<\/p>\n<p>As a result, encryption has become a kind of calling card \u2014 proof that the attackers had access to the data. So cybercriminals finally decided to drop this optional step altogether.<\/p>\n<h2>What businesses should do<\/h2>\n<p>Standard cyberhygiene practices can help protect against a wide range of extortion schemes \u2014 regardless of whether or not they involve encryption:<\/p>\n<ul>\n<li><strong>Run regular, automatic <\/strong><a href=\"https:\/\/www.kaspersky.com\/blog\/smb-backups-reasons\/36322\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>backups<\/strong><\/a><strong>.<\/strong> By storing backups on two types of media\u00a0\u2014 physical and cloud\u00a0\u2014 a business need not fear serious disruption to its operations. After all, the downtime required to restore from backups is nothing compared with the consequences of losing all of its data.<\/li>\n<li><strong>Install patches and updates promptly. <\/strong>For attackers, vulnerabilities remain one of the main entry points into infrastructure. To reduce the risk, we recommend setting up automated update management for operating systems, software, and drivers. It\u2019s also important to scan systems regularly for security gaps, and triage the found vulnerabilities with a focus on critical flaws. <a href=\"https:\/\/www.kaspersky.com.au\/enterprise-security\/vulnerability-management?icid=au_kdaily_placeholder_sm-team_dc0d524985d7541a\" target=\"_blank\" rel=\"noopener\">Specialized vulnerability management solutions<\/a> can help with this.<\/li>\n<li><strong>Strengthen endpoint protection.<\/strong> Set up multi-factor authentication for every system in an infrastructure, and deploy a reliable workstation and server security solution. A <a href=\"https:\/\/www.kaspersky.com.au\/enterprise-security\/unified-monitoring-and-analysis-platform?icid=au_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______\" target=\"_blank\" rel=\"noopener\">SIEM<\/a> or <a href=\"https:\/\/www.kaspersky.com.au\/next?icid=au_kdailyplacehold_acq_ona_smm__onl_b2b_kdaily_wpplaceholder_sm-team___knext____d4bb560012e498a0\" target=\"_blank\" rel=\"noopener\">EDR solution <\/a> can help security specialists gain full visibility into events, and respond to incidents quickly.<\/li>\n<li><strong>Monitor external perimeter. <\/strong>Regularly check the company\u2019s infrastructure (servers, databases, clouds, and legacy subdomains) for open ports and services exposed to the internet.<\/li>\n<li><strong>Adhere to the principle of least privilege.<\/strong> This <a href=\"https:\/\/www.kaspersky.com\/blog\/what-is-the-principle-of-least-privilege\/50232\/\" target=\"_blank\" rel=\"noopener nofollow\">means<\/a> giving users, systems, and processes only the access privileges they need to do their jobs. Revoke unused privileges, and fully disable access for former employees.<\/li>\n<li><strong>Invest in staff training.<\/strong> Attackers still exploit the human element to break into a company\u2019s infrastructure. <a href=\"https:\/\/k-asap.com\/en\/?icid=au_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder____kasap___\" target=\"_blank\" rel=\"noopener\">Raising threat awareness <\/a> among employees can keep them from falling victim to phishing.<\/li>\n<\/ul>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"kaspersky-next\">\n","protected":false},"excerpt":{"rendered":"<p>In April, our experts investigated the PAYLOAD campaign \u2014 where the leverage wasn&#8217;t data encryption but a malicious AD group policy object.<\/p>\n","protected":false},"author":2698,"featured_media":36879,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1999,2993,2994],"tags":[3047,420,422,3164],"class_list":["post-36878","post","type-post","status-publish","format-standard","has-post-thumbnail","category-business","category-enterprise","category-smb","tag-extortion","tag-ransomware","tag-threats","tag-trends"],"hreflang":[{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/ransomware-extortion-without-encryption\/36878\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/ransomware-extortion-without-encryption\/31133\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/ransomware-extortion-without-encryption\/26167\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/ransomware-extortion-without-encryption\/30973\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/ransomware-extortion-without-encryption\/42828\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/ransomware-extortion-without-encryption\/56538\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/ransomware-extortion-without-encryption\/31129\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/ransomware-extortion-without-encryption\/36547\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.au\/blog\/tag\/ransomware\/","name":"Ransomware"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/posts\/36878","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/users\/2698"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/comments?post=36878"}],"version-history":[{"count":0,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/posts\/36878\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/media\/36879"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/media?parent=36878"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/categories?post=36878"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/tags?post=36878"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}