Ransomware Evolution: Extortion Without Encryption
🔒 In a shift noted by Kaspersky experts, ransomware operators are increasingly abandoning encryption and focusing on extortion through access and data theft. The PAYLOAD campaign demonstrated this by abusing Active Directory and GPOs to display ransom notes, change wallpapers, disable accounts, and prove access without encrypting files. Attackers favor data exfiltration because backups negate the leverage of encryption, while leaks threaten reputation and regulatory fines. Standard cyberhygiene remains essential to mitigate these evolving extortion tactics.
