Threat actors have been observed leveraging Group Policy Objects (GPOs) to deliver ransom notes, hijack desktop wallpaper and lock screens, enforce logon banners, and disable local administrator accounts across all domain-joined Windows workstations without dropping a ransomware binary or encrypting any data. This technique is an example of living-off-the-land abuse of trusted Active Directory infrastructure. The actor's goal is operational disruption and the threat of escalation rather than cryptographic denial of data.
The attack chain involves authenticating to the FortiGate SSL VPN using valid but compromised domain credentials, creating a malicious GPO linked at the domain root, staging payload files in SYSVOL, disabling Windows Firewall on all profiles, and exfiltrating data. The entire attack lives inside Active Directory itself, making it difficult for traditional endpoint detection and response tools to detect.[/subscribe_to_unlock_form]
Threat actors have been observed leveraging Group Policy Objects (GPOs) to deliver ransom notes, hijack desktop wallpaper and lock screens, enforce logon banners, and disable local administrator accounts across all domain-joined Windows workstations without dropping a ransomware binary or encrypting any data. This technique is an example of living-off-the-land abuse of trusted Active Directory infrastructure. The actor's goal is operational disruption and the threat of escalation rather than cryptographic denial of data.
The attack chain involves authenticating to the FortiGate SSL VPN using valid but compromised domain credentials, creating a malicious GPO linked at the domain root, staging payload files in SYSVOL, disabling Windows Firewall on all profiles, and exfiltrating data. The entire attack lives inside Active Directory itself, making it difficult for traditional endpoint detection and response tools to detect.[emaillocker id="1283"]
The defensive implication is stark: an organization whose detection strategy depends on catching a ransomware executable would have seen nothing until the first endpoint rebooted and the ransom wallpaper appeared. To detect such threats, organizations should focus on monitoring Group Policy Objects and SYSVOL for suspicious activity.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Initial access | T1078 | Valid Accounts | - |
| Initial access | T1078.002 | Valid Accounts | Domain Accounts |
| Initial access | T1133 | External Remote Services | - |
| Defence Evasion | T1484.001 | Domain or Tenant Policy Modification | Group Policy Modification |
| Collection | T1005 | Data from Local System | - |
| Impact | T1491.001 | Defacement | Internal Defacement |
| Impact | T1531 | Account Access Removal | - |
The following reports contain further technical details:
[/emaillocker]