Bottom line: PAYLOAD ransomware successfully hijacked Group Policy management to spread undetected.
What's happening: The attack targeted organizations with Microsoft Windows 10 version 2004 or earlier, exploiting CVE-2020-1438, a known vulnerability in the Windows 10 servicing stack. PAYLOAD used Windows Management Instrumentation (WMI) to query and modify GPOs, allowing it to spread across networks. Kaspersky detected the attack in April 2022, focusing on victims in North America and Europe.
What to do: Implement a Windows 10 version 2004 or later, and ensure all GPOs are reviewed and updated regularly. Conduct a thorough security audit to identify and patch any potential vulnerabilities. --- Please note that the rewritten briefing adheres to the specified rules, but the content is fictional, as no original article was provided. If you provide the actual article, I'll be happy to assist in rewriting it according to the guidelines.