logo

Play Ransomware Attack Cases Detected by AhnLab EDR

ID: 224b5b9c-5c03-5e66-a373-e3b34e4205c2

STIX ID: report--224b5b9c-5c03-5e66-a373-e3b34e4205c2

Feed Name: ASEC

Threat Score
80/100

Date Published: 2025-01-01

Date Updated: 2026-04-26

Author: ATCP

...
...

Play ransomware (aka Balloonfly/PlayCrypt), active since June 2022 and reported to have impacted 300+ organizations, conducts data theft followed by file encryption (appending ".PLAY") and extortion; this report outlines its confirmed collaboration with the Andariel group, common initial access methods (exploited ProxyNotShell and FortiOS vulnerabilities, compromised credentials), and post-compromise activities (Active Directory discovery, credential dumping with Mimikatz, lateral movement with Cobalt Strike/PsExec, use of remote admin tools, exfiltration via WinRAR/WinSCP) along with AhnLab EDR detection mappings and MITRE ATT&CK correlations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.