logo

Play’s New Tactics Bypass Traditional Defenses. Are You Ready? by Lucie Cardiet

ID: 481d76b0-fd16-5bf9-ad3e-147d31d39c03

STIX ID: report--481d76b0-fd16-5bf9-ad3e-147d31d39c03

Feed Name: Vectra AI Blog

Threat Score
78/100

Date Published: 2025-06-12

Date Updated: 2026-05-01

...
...

Play ransomware is actively exploiting CVE-2024-57727 in SimpleHelp to gain remote access, then using PowerShell and custom-built tooling (e.g., HRsword.exe, Grixba, Usysdiag.exe, modified PsExec) to disable defenses, exfiltrate data, and deploy per-victim ransomware — including variants that target VMware ESXi. The group conducts double-extortion and increasingly uses direct human pressure (emails and phone calls); the report urges behavior-based detection across hybrid environments and highlights Vectra AI as a vendor solution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.