logo

Double-Extortion Play Ransomware Strikes 300 Organizations Worldwide

ID: 8b5f4b8a-6cc8-54b3-98af-04a9cb7aae89

STIX ID: report--8b5f4b8a-6cc8-54b3-98af-04a9cb7aae89

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2023-12-19

Date Updated: 2026-04-23

Author: [email protected] (The Hacker News)

...
...

This advisory summarizes activity attributed to the Play ransomware operation (aka Balloonfly/PlayCrypt), which emerged in 2022 and has affected roughly 300 organizations by October 2023. Play leverages exploited vulnerabilities in Microsoft Exchange and Fortinet appliances, uses a double-extortion RaaS model with data exfiltration followed by encryption, and employs public and bespoke tools (AdFind, Grixba, Cobalt Strike, Mimikatz, etc.) to disable defenses, move laterally, and harvest backups and credentials. The report also situates Play among contemporaneous ransomware groups and trends, including collaboration between gangs, the rise of RaaS, and shifts toward vulnerability-based initial access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.