logo

DECODING GRIXBA — A PLAY RANSOMWARE SCANNER

ID: 7f7f24eb-f0b5-56f7-9e9d-afd536733418

STIX ID: report--7f7f24eb-f0b5-56f7-9e9d-afd536733418

Feed Name: THE RAVEN FILE

Threat Score
85/100

Date Published: 2026-06-08

Date Updated: 2026-06-08

Author: RakeshKrish

...
...

Play Ransomware's in-house infostealer 'Grixba' (four samples across 26 months) performs broad host and credential reconnaissance prior to encryption; the report documents version-specific features (v1 → v1.5 → v2 → v3), IOCs (hashes, drop path, mutex, PIA VPN IP), persistent behaviors (WMI/WinRM enumeration, event log clearing), detection/evasion trade-offs, and operational weaknesses defenders can exploit.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.