Kaspersky Lab has uncovered an unusual attack on a manufacturing enterprise in the Middle East. Ransomware operators managed to block workstations and display ransom demands on them, even though there was no traditional encryptor in the network at all.
The key to the attack was compromised accounts with elevated privileges. Using standard remote access tools and VPN, the attackers penetrated the corporate network in such a way that their activity could appear as the work of a regular IT specialist.
Next, the attackers gained control over Active Directory — a system through which companies centrally manage employee computers. In it, they created a malicious Group Policy called Payload. Such rules are usually used by administrators for mass device configuration, but in this case, they were used to change wallpapers and lock screens, display ransom demands, and disable administrative accounts.
This resulted in an unusual scenario: instead of installing malware, the attackers used a trusted mechanism of the corporate infrastructure itself. After policy updates, the changes automatically spread across the network, so simply scanning for viruses is no longer enough to detect such an attack.
In parallel, the attackers stole valuable corporate data and then published it on the dark web, using the leak as additional pressure on the company. Kaspersky Lab notes that ransomware operators are increasingly moving away from classic encryption and focusing on information theft, access blocking, and the threat of public disclosure.
Read more on the topic:
- Trap in a working file: hackers attack companies through Word and Excel documents
- The Leak Reached a Percentage: Hackers Increased Pressure on Russian Businesses, Threatening to Disclose Information to Regulators and the Public
- Hackers Change Tactics: Now They Hide Within Ordinary Business Processes