INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Group Policy Hijacked by Ransomware Using Active Directory GPO

| 2026-10-02 09:20 CRITICAL HIGH RANSOMWARE & EXTORTION
Executive Summary
AI-generated
Authorities have made significant strides in combating the KillSec ransomware group, which has been linked to hundreds of cyber-attacks worldwide. The operation resulted in eight house searches across Spain, Greece, Romania, and the UK, yielding evidence and assets seized alongside three provisional arrests, including a 16-year-old suspected administrator and main operator. A Dutch national living in the UK has also been indicted by US authorities on charges related to KillSec. Europol reports that the group exploited software vulnerabilities and cloud storage access points to target organizations such as hospitals, government bodies, and financial institutions. The operation, dubbed Operation KillSwitch, led to the seizure of at least 110TB of stolen data and prevented its exposure. German police were involved in the campaign, which also resulted in the arrest of Fouad Eltibrizi, aka Archduke, on hacking and extortion-related offenses.
Technical Mitigations AI-generated
• Implementing regular software updates and patches to prevent exploitation of vulnerabilities. • Enforcing strict access controls on cloud storage, including multi-factor authentication and least privilege principles. • Regularly monitoring for suspicious activity and implementing incident response plans to quickly contain and respond to security breaches.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

dc•••••.local
th•••••.local
gp•••••.inf
sc•••••.xml
RE•••••.txt
he•••••.txt
ki•••••.exe
ki•••••.exe
010865••••••••••••••••••••••••••
bea5e2••••••••••••••••••••••••••
104.164.•••.•••
146.70.•••.•••
149.102.•••.•••
192.42.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation KillSwitchOperation KillSwitch BlackCatBlackCatRyukRyukALPHVALPHV
Target & Sectors
MIDDLE_EAST MIDDLE_EAST NORTH_AMERICA NORTH_AMERICA BENELUX BENELUX DACH DACH healthhealth manufacturingmanufacturing
Incident Timeline
‎April 2026
Threat actors used a ransomware attack to target the manufacturing organization in the Middle East.
industry Manufacturing
target_region MIDDLE_EAST
organisation Kaspersky’s Global Emergency Response Team
‎11 April
Threat actors used initial access to target KillSec, a ransomware group, on April 11.
‎13 April
Threat actors used a Group Policy Object (GPO) to target and exfiltrate data from endpoints on April 13, with the policy update being cached but not yet applied until the next day.
tactic Exfiltration
organisation MFT
‎13 April Second GPO
Threat actors wrote the hello.txt and payload.jpg files to a compromised Windows system.
infrastructure Windows
observable hello.txt
organisation payload.jpg
‎13 April: HKLM\
The ransomware group, KillSec, applied the PAYLOAD payload to a Windows workstation on April 13.
general_metric 5 Event ID
organisation State
‎14 April
Threat actors used a one-day delay detonation to target the killSec ransomware group with an attack that was set to occur on April 14.
‎15 April
Threat actors behind the KillSec ransomware group were targeted by law enforcement with arrests and seizures on 15 April.
‎16 April Assessment
Threat actors behind the KillSec ransomware group were targeted by law enforcement with simultaneous arrests and seizures on 16 April.
‎August 2026
A 18-year-old suspected developer was indicted by US authorities in August 2026 on charges related to their alleged involvement with the KillSec ransomware group.
general_metric 18 developer
‎September 30
British police arrested Fouad Eltibrizi, aka Archduke, on September 30 for hacking and extortion-related offenses.
target_region United Kingdom
tactic Extortion
attribution Fouad Eltibrizi
‎2026/10/02
Threat actors used a Group Policy Object (GPO) to hijack Windows systems, deliver ransom notes and disable the local administrator account across every domain-joined workstation.
organisation Group-IB
victims 274 claimed victims
infrastructure Fortigate
organisation RSOP
infrastructure Windows
infrastructure Linux
organisation Microsoft
organisation PsExec
organisation LockBit
organisation SYSVOL Group
organisation GPO Preferences
organisation Backup
organisation BYOVD
organisation Ransomware
organisation Sysmon Event ID 6
organisation Invalid
organisation Driver
organisation Code Integrity
organisation OOTB] Group
organisation ENG
data_breach 110 TB
organisation VMware
organisation Event ID 7036
organisation Sysmon Event ID 5
organisation Windows Volume Shadow Copies
organisation Initial Access
organisation Initial Access T1133
organisation Privilege Escalation T1078.002
organisation Windows Firewall
organisation GPO Security
organisation Command
organisation Registry (Computer
organisation Modify
organisation the “Group Policy Registry
organisation Firewall Off GPO
organisation Windows Event Log
organisation Windows Event Collector
organisation EDR
organisation Windows Security Event ID
organisation Event ID 1102
organisation Sysmon Event ID 1
organisation VSS
organisation ETW
organisation Event Tracing for
organisation DLL
organisation Unexpected
organisation Sysmon
organisation Windows Event Logs
organisation Deploy Windows LAPS
organisation Detection of Windows Event Log
organisation KillSec
organisation Europol
organisation Group
organisation FortiGate SSL VPN
organisation SSL
organisation MFA
organisation Source SYSVOL\hello.txt → Desktop
organisation the “Group Policy Files
organisation Rotate
organisation Set payload.jpg
organisation the Files Group Policy Preference CSE
organisation Enumeration of Security, System, Application
organisation IP
organisation Group Policy Object
organisation GPO
organisation Active Directory
organisation Group Policy
organisation GPC
organisation GPT
organisation SYSVOL
organisation Ransom
organisation IAB
organisation Group Policy Creator Owners
organisation CSE
organisation Files (Group Policy Preference
organisation PAYLOAD GPO
organisation PAYLOAD
organisation Run/RunOnce
organisation WMI
organisation MBR
organisation vCenter
organisation EtwRegister
organisation Bulk VM
organisation Delete
organisation Clean SYSVOL
organisation Adopt Privileged Access Workstations
organisation PAW
organisation Privileged Identity Management
organisation PIM
organisation Kaspersky
organisation Kaspersky SIEM
organisation Kaspersky Endpoint Detection and
organisation Kaspersky EDR Expert
Tactical Metrics
Metrics
victims
274
Claimed Victims
Metrics
data_breach
110
Tb
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎Fortigate
Affected Product
Metrics
infrastructure
‎Linux
Affected Product
Intelligence Sources