Play Ransomware Group Exploits Windows CLFS Zero-Day Vulnerability
ID: 3720c259-68e4-596e-a00b-6502696ff35f
STIX ID: report--3720c259-68e4-596e-a00b-6502696ff35f
Feed Name: Halcyon Blog
Play ransomware operators exploited a zero-day Windows CLFS privilege-escalation vulnerability (CVE-2025-29824) against an unnamed U.S. organization, gaining access likely via a public-facing Cisco ASA, deploying the custom infostealer "Grixba," and using malicious artifacts (PDUDrv.blf, clssrv.inf) plus batch scripts (servtask.bat, cmdpostfix.bat) to escalate privileges, dump registry hives, create an admin account, map Active Directory, and remove traces; Microsoft patched the flaw after attackers used it and no ransomware was deployed in this case, but the incident illustrates elevated ransomware operator sophistication and exploitation of zero-days in the wild.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
