FBI: Over 900 Organizations Disrupted by Play Ransomware Attacks
ID: 4931f531-46bf-5100-a20e-60136bd4a938
STIX ID: report--4931f531-46bf-5100-a20e-60136bd4a938
Feed Name: Halcyon Blog
Since mid-2022 the Play ransomware group has carried out hundreds of attacks (reported ~900), operating as a Ransomware-as-a-Service actor that exploits unpatched vulnerabilities (e.g., CVE-2024-57727 and other remote access flaws) to gain access, uses a mix of custom and commodity tooling (PowerTool, SystemBC, Cobalt Strike, Mimikatz, Grixba, VSS utilities, Plink/AnyDesk) to evade detection and move laterally, employs intermittent encryption with AES-256/RSA-4096 and double-extortion data theft/leak threats, and targets high-value industries with ransom demands from six-figure to multi-million dollar ranges.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
