logo

The Curious Case of PlayBoy Locker

ID: e614bb6d-bbb1-5af3-8191-d67463bbea39

STIX ID: report--e614bb6d-bbb1-5af3-8191-d67463bbea39

Feed Name: Cybereason Blog

Threat Score
78/100

Date Published: 2025-03-25

Date Updated: 2026-04-27

Author: Cybereason Security Services Team

...
...

Cybereason analyzes PlayBoy Locker, a Ransomware-as-a-Service (RaaS) observed on darknet forums that provides affiliates with customizable binaries for Windows, ESXi, and NAS, features LDAP-based AD worming, multithreaded file encryption using hc-128 and curve25519, shadow copy deletion, process/service termination, web-based builder and admin panels, and includes IOCs and defensive recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.