Play Ransomware Attack Cases Detected by AhnLab EDR
ID: 224b5b9c-5c03-5e66-a373-e3b34e4205c2
STIX ID: report--224b5b9c-5c03-5e66-a373-e3b34e4205c2
Feed Name: ASEC
Play ransomware (aka Balloonfly/PlayCrypt), active since June 2022 and reported to have impacted 300+ organizations, conducts data theft followed by file encryption (appending ".PLAY") and extortion; this report outlines its confirmed collaboration with the Andariel group, common initial access methods (exploited ProxyNotShell and FortiOS vulnerabilities, compromised credentials), and post-compromise activities (Active Directory discovery, credential dumping with Mimikatz, lateral movement with Cobalt Strike/PsExec, use of remote admin tools, exfiltration via WinRAR/WinSCP) along with AhnLab EDR detection mappings and MITRE ATT&CK correlations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
