IOC Radar

Indicators are what attackers leave behind. Stolen credentials are what they arrive with.

Check Your Exposure
TLP:WHITE14 IOCs

Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO

SE
Securelist
Published September 21, 2026Original Report

Threat Actors

Malware Families

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYBlackCatINFRASTRUCTURE104.164.55.46192.42.116.52149.102.229.154CAPABILITYBlackCatLockBitPsExecVICTIMunknown
Adversary(1)
Infrastructure(6)
Capability(4)
Victim

Indicators of Compromise

Indicators of Compromise14

TypeIndicatorConfidenceScoreFirst Seen
IP104.164.55.46
exploitintel-blogmalware
High
58
Sep 22, 26
IP192.42.116.52
exploitintel-blogmalware
High
58
Sep 22, 26
IP149.102.229.154
exploitintel-blogmalware
High
58
Sep 22, 26
IP37.19.210.12
exploitintel-blogmalware
High
58
Sep 22, 26
IP104.28.163.162
exploitintel-blogmalware
High
58
Sep 22, 26
IP192.42.116.50
exploitintel-blogmalware
High
58
Sep 22, 26
IP192.42.116.97
exploitintel-blogmalware
High
58
Sep 22, 26
IP64.190.76.14
exploitintel-blogmalware
High
58
Sep 22, 26
IP192.42.116.12
exploitintel-blogmalware
High
58
Sep 22, 26
MD50108656a3e1ade6ca4f21b084f5e1208
exploitfile-hashintel-blog
High
56
Sep 22, 26
IP104.28.162.228
exploitintel-blogmalware
High
58
Sep 22, 26
IP192.42.116.56
exploitintel-blogmalware
High
58
Sep 22, 26
MD5bea5e267f24d7da59f6821bffdbff293
exploitfile-hashintel-blog
High
56
Sep 22, 26
IP146.70.117.239
exploitintel-blogmalware
High
58
Sep 22, 26

IOC Relationship Graph

IOC Relationship Graph14 total IOCs
IPMD5
IP12MD52Actors1Malware4REPORTGroup Policy hijacked: PAYBlackCatBlackCatLockBitPsExecRyuk
scroll to zoom · drag to pan · click IOC to open