Double-Extortion Play Ransomware Strikes 300 Organizations Worldwide
ID: 8b5f4b8a-6cc8-54b3-98af-04a9cb7aae89
STIX ID: report--8b5f4b8a-6cc8-54b3-98af-04a9cb7aae89
Feed Name: The Hacker News
This advisory summarizes activity attributed to the Play ransomware operation (aka Balloonfly/PlayCrypt), which emerged in 2022 and has affected roughly 300 organizations by October 2023. Play leverages exploited vulnerabilities in Microsoft Exchange and Fortinet appliances, uses a double-extortion RaaS model with data exfiltration followed by encryption, and employs public and bespoke tools (AdFind, Grixba, Cobalt Strike, Mimikatz, etc.) to disable defenses, move laterally, and harvest backups and credentials. The report also situates Play among contemporaneous ransomware groups and trends, including collaboration between gangs, the rise of RaaS, and shifts toward vulnerability-based initial access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
