Threat Advisory

Active Directory GPO Flaw Grants Domain-Wide Control to Attackers

Threat: Malware
Threat Actor Name: BlackCat
Threat Actor Type: Financially Motivated
Targeted Region: Middle East
Alias: ALPHV, Noberus
Threat Actor Region: Russia
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Threat actors have been observed leveraging Group Policy Objects (GPOs) to deliver ransom notes, hijack desktop wallpaper and lock screens, enforce logon banners, and disable local administrator accounts across all domain-joined Windows workstations without dropping a ransomware binary or encrypting any data. This technique is an example of living-off-the-land abuse of trusted Active Directory infrastructure. The actor's goal is operational disruption and the threat of escalation rather than cryptographic denial of data.

The attack chain involves authenticating to the FortiGate SSL VPN using valid but compromised domain credentials, creating a malicious GPO linked at the domain root, staging payload files in SYSVOL, disabling Windows Firewall on all profiles, and exfiltrating data. The entire attack lives inside Active Directory itself, making it difficult for traditional endpoint detection and response tools to detect.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Threat actors have been observed leveraging Group Policy Objects (GPOs) to deliver ransom notes, hijack desktop wallpaper and lock screens, enforce logon banners, and disable local administrator accounts across all domain-joined Windows workstations without dropping a ransomware binary or encrypting any data. This technique is an example of living-off-the-land abuse of trusted Active Directory infrastructure. The actor's goal is operational disruption and the threat of escalation rather than cryptographic denial of data.

The attack chain involves authenticating to the FortiGate SSL VPN using valid but compromised domain credentials, creating a malicious GPO linked at the domain root, staging payload files in SYSVOL, disabling Windows Firewall on all profiles, and exfiltrating data. The entire attack lives inside Active Directory itself, making it difficult for traditional endpoint detection and response tools to detect.[emaillocker id="1283"]

The defensive implication is stark: an organization whose detection strategy depends on catching a ransomware executable would have seen nothing until the first endpoint rebooted and the ransom wallpaper appeared. To detect such threats, organizations should focus on monitoring Group Policy Objects and SYSVOL for suspicious activity.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1078 Valid Accounts -
Initial access T1078.002 Valid Accounts Domain Accounts
Initial access T1133 External Remote Services -
Defence Evasion T1484.001 Domain or Tenant Policy Modification Group Policy Modification
Collection T1005 Data from Local System -
Impact T1491.001 Defacement Internal Defacement
Impact T1531 Account Access Removal -

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu