logo

#StopRansomware: Play Ransomware

ID: 256bdc93-7949-5146-9d34-5ca932cffff0

STIX ID: report--256bdc93-7949-5146-9d34-5ca932cffff0

Feed Name: CISA Cybersecurity Advisories

Threat Score
80/100

Date Published: 2023-12-11

Date Updated: 2026-04-19

Author: CISA

...
...

This joint FBI/CISA/ASD advisory documents the Play (Playcrypt) ransomware group's widespread, double-extortion operations affecting organizations across multiple regions, detailing initial access vectors (valid account abuse, RDP/VPN, exploitation of multiple CVEs including FortiOS, Microsoft Exchange, and SimpleHelp), discovery/defense-evasion and lateral-movement tooling (Grixba infostealer, Cobalt Strike, Mimikatz, SystemBC), exfiltration and intermittent AES‑RSA encryption behavior (including an ESXi variant), plus IOCs (file hashes, keys) and YARA/Suricata detection rules, with prioritized mitigations and reporting guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.