logo

Play Ransomware Group Exploits Windows CLFS Zero-Day Vulnerability

ID: 3720c259-68e4-596e-a00b-6502696ff35f

STIX ID: report--3720c259-68e4-596e-a00b-6502696ff35f

Feed Name: Halcyon Blog

Threat Score
85/100

Date Published: 2025-05-07

Date Updated: 2026-04-28

...
...

Play ransomware operators exploited a zero-day Windows CLFS privilege-escalation vulnerability (CVE-2025-29824) against an unnamed U.S. organization, gaining access likely via a public-facing Cisco ASA, deploying the custom infostealer "Grixba," and using malicious artifacts (PDUDrv.blf, clssrv.inf) plus batch scripts (servtask.bat, cmdpostfix.bat) to escalate privileges, dump registry hives, create an admin account, map Active Directory, and remove traces; Microsoft patched the flaw after attackers used it and no ransomware was deployed in this case, but the incident illustrates elevated ransomware operator sophistication and exploitation of zero-days in the wild.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.