Skip to content
The Nexus
Group profile33 claimed in last 30d102 total tracked

play

Forward this

Initially observed in June 2022, the Play ransomware (a.k.a PlayCrypt) operates through double extortion, targeting numerous organizations in Latin America. Its Initial Access method is quite similar to other ransomwares, involving attacks such as Phishing, Exposed Services to the Internet, and Valid Account compromises. On April 19, 2023, the security company Symantec published two new tools developed by the Play group. These tools allow the malicious actor to enumerate and exfiltrate data from the internal network. The post mentions the following: 'Play threat actors use the .NET infostealer to enumerate software and services via WMI, WinRM, Remote Registry, and Remote Service. The malware checks for the existence of security and backup software, as well as remote administration tools and other programs, saving the information in .CSV files that are compressed into a .ZIP file for later manual exfiltration by threat actors.'Source: https://github.com/crocodyli/ThreatActors-TTPs

First seen: May 19 · 14:53 UTCLast seen: Aug 20 · 17:27 UTCTracked since: 2022-11-26
Sectors hit
  • Unspecified8
  • Technology6
  • Manufacturing6
  • Business Services6
  • Professional Services4
  • Financial Services4
  • Consumer Services4
  • Telecommunication3
Countries hit
  • United States33
  • Netherlands3
  • United Kingdom3
  • Germany3
  • Sweden1
  • Malta1
  • Latvia1
  • Italy1
  • Spain1
  • Canada1
MITRE ATT&CK · observed TTPs15 tactics

Tactics and techniques attributed to PLAY by ransomware.live's curated TTP catalog. Identifiers link to the canonical MITRE ATT&CK reference for each tactic or sub-technique.

  • TA0001Initial Access
    • T1078Valid Accounts

      Compromised VPN credentials used to authenticate directly to victim networks.

    • T1078.002Valid Accounts: Domain Accounts

      [Play](https://attack.mitre.org/groups/G1040) has used valid domain accounts for access.(Citation: Trend Micro Ransomware Spotlight Play July 2023)

    • T1078.003Valid Accounts: Local Accounts

      [Play](https://attack.mitre.org/groups/G1040) has used valid local accounts to gain initial access.(Citation: Trend Micro Ransomware Spotlight Play July 2023)

    • T1133External Remote Services

      [Play](https://attack.mitre.org/groups/G1040) has used Remote Desktop Protocol (RDP) and Virtual Private Networks (VPN) for initial access.(Citation: CISA Play Ransomware Advisory December 2023)(Citation: Trend Micro Ransomware Spotlight Play July 2023)

    • T1190Exploit Public-Facing Application

      Play exploits vulnerabilities in Microsoft Exchange (ProxyNotShell CVE-2022-41040/CVE-2022-41082), FortiOS SSL VPN (CVE-2018-13379), and RDP to gain initial access.

  • TA0002Execution
    • T1053.005Scheduled Task/Job: Scheduled Task

      Scheduled tasks used for payload persistence and execution across compromised hosts.

    • T1059Command and Scripting Interpreter
    • T1059.001Command and Scripting Interpreter: PowerShell

      PowerShell scripts used for payload execution and post-exploitation tooling deployment.

    • T1059.003Command and Scripting Interpreter: Windows Command Shell

      [Play](https://attack.mitre.org/groups/G1040) has used a batch script to remove indicators of its presence on compromised hosts.(Citation: Trend Micro Ransomware Spotlight Play July 2023)

  • TA0003Persistence
    • T1078.002Valid Accounts: Domain Accounts

      [Play](https://attack.mitre.org/groups/G1040) has used valid domain accounts for access.(Citation: Trend Micro Ransomware Spotlight Play July 2023)

    • T1078.003Valid Accounts: Local Accounts

      [Play](https://attack.mitre.org/groups/G1040) has used valid local accounts to gain initial access.(Citation: Trend Micro Ransomware Spotlight Play July 2023)

    • T1133External Remote Services

      [Play](https://attack.mitre.org/groups/G1040) has used Remote Desktop Protocol (RDP) and Virtual Private Networks (VPN) for initial access.(Citation: CISA Play Ransomware Advisory December 2023)(Citation: Trend Micro Ransomware Spotlight Play July 2023)

  • TA0004Privilege Escalation
    • T1078.002Valid Accounts: Domain Accounts

      [Play](https://attack.mitre.org/groups/G1040) has used valid domain accounts for access.(Citation: Trend Micro Ransomware Spotlight Play July 2023)

    • T1078.003Valid Accounts: Local Accounts

      [Play](https://attack.mitre.org/groups/G1040) has used valid local accounts to gain initial access.(Citation: Trend Micro Ransomware Spotlight Play July 2023)

  • TA0005Defense Evasion
    • T1027Obfuscated Files or Information

      Play ransomware payloads are split into multiple parts to bypass AV scanning; parts reassembled on target systems.

    • T1070Indicator Removal
    • T1070.001Indicator Removal: Clear Windows Event Logs

      Windows event logs wiped to remove forensic evidence using wevtutil.

    • T1484Domain or Tenant Policy Modification
    • T1484.001Domain or Tenant Policy Modification: Group Policy Modification
    • T1562.001Disable or Modify Tools

      Security tools including Windows Defender and AV products disabled prior to encryption.

  • TA0005Stealth
    • T1027.010Obfuscated Files or Information: Command Obfuscation

      [Play](https://attack.mitre.org/groups/G1040) has used Base64-encoded PowerShell scripts for post exploit activities on compromised hosts.(Citation: Trend Micro Ransomware Spotlight Play July 2023)

    • T1070.004Indicator Removal: File Deletion

      [Play](https://attack.mitre.org/groups/G1040) has used tools including [Wevtutil](https://attack.mitre.org/software/S0645) to remove malicious files from compromised hosts.(Citation: Trend Micro Ransomware Spotlight Play July 2023)

    • T1078.002Valid Accounts: Domain Accounts

      [Play](https://attack.mitre.org/groups/G1040) has used valid domain accounts for access.(Citation: Trend Micro Ransomware Spotlight Play July 2023)

    • T1078.003Valid Accounts: Local Accounts

      [Play](https://attack.mitre.org/groups/G1040) has used valid local accounts to gain initial access.(Citation: Trend Micro Ransomware Spotlight Play July 2023)

  • TA0006Credential Access
    • T1003OS Credential Dumping
    • T1003.001OS Credential Dumping: LSASS Memory

      Mimikatz and similar tools used for LSASS memory dumping to harvest credentials.

    • T1003.003OS Credential Dumping: NTDS

      NTDS.dit extracted from domain controllers to obtain all domain account hashes.

    • T1552Unsecured Credentials
  • TA0007Discovery
    • T1016System Network Configuration Discovery
    • T1018Remote System Discovery

      [Play](https://attack.mitre.org/groups/G1040) has used tools such as [AdFind](https://attack.mitre.org/software/S0552), [Nltest](https://attack.mitre.org/software/S0359), and [BloodHound](https://attack.mitre.org/software/S0521) to enumerate shares and hostnames on compromised networks.(Citation: Trend Micro Ransomware Spotlight Play July 2023)

    • T1046Network Service Discovery

      Network scanning tools used to enumerate hosts, services, and potential lateral movement targets.

    • T1057Process Discovery

      [Play](https://attack.mitre.org/groups/G1040) has used the information stealer Grixba to check for a list of security processes.(Citation: Trend Micro Ransomware Spotlight Play July 2023)

    • T1082System Information Discovery

      [Play](https://attack.mitre.org/groups/G1040) has leveraged tools to enumerate system information.(Citation: Trend Micro Ransomware Spotlight Play July 2023)

    • T1083File and Directory Discovery

      [Play](https://attack.mitre.org/groups/G1040) has used the Grixba information stealer to list security files and processes.(Citation: Trend Micro Ransomware Spotlight Play July 2023)

    • T1087.002Account Discovery: Domain Account

      Active Directory enumeration to identify privileged accounts and high-value targets.

    • T1518Software Discovery
    • T1518.001Software Discovery: Security Software Discovery
  • TA0008Lateral Movement
    • T1021.001Remote Services: Remote Desktop Protocol

      RDP used for lateral movement across victim networks.

    • T1021.002Remote Services: SMB/Windows Admin Shares

      PsExec and SMB used to propagate payloads laterally.

    • T1570Lateral Tool Transfer
  • TA0009Collection
    • T1560Archive Collected Data
    • T1560.001Archive Collected Data: Archive via Utility

      WinRAR used to compress and archive stolen data prior to exfiltration.

  • TA0010Exfiltration
    • T1030Data Transfer Size Limits

      [Play](https://attack.mitre.org/groups/G1040) has split victims' files into chunks for exfiltration.(Citation: CISA Play Ransomware Advisory December 2023)(Citation: Trend Micro Ransomware Spotlight Play July 2023)

    • T1048Exfiltration Over Alternative Protocol

      WinSCP and Rclone used to exfiltrate data to actor-controlled infrastructure and cloud storage ahead of encryption.

  • TA0011Command and Control
    • T1105Ingress Tool Transfer

      [Play](https://attack.mitre.org/groups/G1040) has used [Cobalt Strike](https://attack.mitre.org/software/S0154) to download files to compromised machines.(Citation: Trend Micro Ransomware Spotlight Play July 2023)

    • T1219Remote Access Software

      Cobalt Strike, SystemBC, and AnyDesk used as C2 frameworks for persistent access.

  • TA0040Impact
    • T1486Data Encrypted for Impact

      Play ransomware uses AES-RSA hybrid encryption. Files appended with .play extension. Targets Windows and Linux/ESXi environments. Double extortion model with data published on Play leak site. Notable for NOT including ransom note in individual encrypted files — single note left at root of C: drive.

    • T1489Service Stop

      Database, mail, backup, and security services terminated before encryption to ensure maximum file access.

    • T1490Inhibit System Recovery

      Shadow copies deleted and Windows recovery disabled to prevent victim restoration of files.

    • T1657Financial Theft
  • TA0042Resource Development
    • T1587.001Develop Capabilities: Malware

      [Play](https://attack.mitre.org/groups/G1040) developed and employ [Playcrypt](https://attack.mitre.org/software/S1162) ransomware.(Citation: Trend Micro Ransomware Spotlight Play July 2023)(Citation: CISA Play Ransomware Advisory December 2023)

    • T1588.002Obtain Capabilities: Tool

      [Play](https://attack.mitre.org/groups/G1040) has used multiple tools for discovery and defense evasion purposes on compromised hosts.(Citation: CISA Play Ransomware Advisory December 2023)

  • TA0112Defense Impairment
    • T1685Disable or Modify Tools

      [Play](https://attack.mitre.org/groups/G1040) has used tools including GMER, IOBit, and PowerTool to disable antivirus software.(Citation: CISA Play Ransomware Advisory December 2023)(Citation: Trend Micro Ransomware Spotlight Play July 2023)

    • T1685.005Disable or Modify Tools: Clear Windows Event Logs

      [Play](https://attack.mitre.org/groups/G1040) has used tools to remove log files on targeted systems.(Citation: CISA Play Ransomware Advisory December 2023)(Citation: Trend Micro Ransomware Spotlight Play July 2023)

Recent claimed victims
TechnologyUnited StatesAug 20 · 17:28 UTC

Be Media

www.bemedia.com
ManufacturingLatviaAug 20 · 17:27 UTC

Latoplast

www.latoplast.com
TechnologyUnited StatesAug 18 · 17:31 UTC

Coltrane Systems

www.coltranesystems.com
Aug 17 · 22:31 UTC

Bridgeport Capital Services

Aug 17 · 22:31 UTC

Woodhaven Association

Financial ServicesUnited StatesAug 17 · 20:27 UTC

Bridgeport Capital Services

www.bridgeportcapital.com
Retail & E-CommerceUnited StatesAug 17 · 20:26 UTC

Sam Pack Auto Group

www.sampack.com
Aug 9 · 21:35 UTC

Marconi Industrial Services

Professional ServicesUnited KingdomAug 9 · 19:26 UTC

MIE Solutions

www.mie-solutions.com
Aug 9 · 19:26 UTC

Rilpa Enterprises

www.helis.com
ManufacturingItalyAug 9 · 18:56 UTC

Marconi Industrial Services

www.marconi-spa.com
Professional ServicesAug 6 · 19:56 UTC

Signature Services

www.signatureservices.net
Financial ServicesUnited StatesAug 6 · 19:56 UTC

GCATS Investments

www.gcatstx.com
Aug 5 · 01:46 UTC

Preferred Financial Group

TechnologyUnited StatesAug 4 · 16:26 UTC

First Tek

www.first-tek.com
Financial ServicesUnited StatesAug 4 · 16:25 UTC

Preferred Financial Group

www.preferredfinancial.com
Retail & E-CommerceUnited StatesAug 1 · 19:04 UTC

The Butcher Brothers

www.thebutcherbrotherscorp.com
ManufacturingUnited StatesAug 1 · 19:04 UTC

Sigma Plastics Group

www.sigmaplasticsgroup.com
Professional ServicesUnited StatesAug 1 · 19:03 UTC

Cambridge Management

www.cambridgemgmt.net
HospitalitySpainJul 23 · 20:29 UTC

Record Go Alquiler

www.recordrentacar.com
Retail & E-CommerceUnited StatesJul 23 · 20:29 UTC

Restaurant Depot

www.restaurantdepot.com
United StatesJul 23 · 20:28 UTC

The DeBruler

www.tax-mt.com
Jul 22 · 18:56 UTC

Kreysler & Associates

Business ServicesMaltaJul 21 · 20:15 UTC

Tax MT

www.tax-mt.com
Professional ServicesUnited StatesJul 21 · 18:10 UTC

Kreysler & Associates

www.kreysler.com
Jul 16 · 20:52 UTC

Boston Electric and Telephone

TelecommunicationUnited StatesJul 16 · 18:31 UTC

Boston Electric and Telephone

www.betcorp.com
United KingdomJul 16 · 18:31 UTC

Wring Group

www.wringgroup.co.uk
ManufacturingNetherlandsJul 16 · 17:57 UTC

AG Scholtes

www.agscholtes.nl
HealthcareAndorraJul 16 · 17:57 UTC

Andorra Life

www.andorralife.com
Business ServicesSwedenJul 16 · 17:56 UTC

Svensk Direktreklam

www.sdr.se
Jul 7 · 19:53 UTC

Preneed Funeral Programs

Consumer ServicesUnited StatesJul 7 · 17:56 UTC

Preneed Funeral Programs

www.preneed.net
Jul 7 · 17:30 UTC

Kevin Bao Lenguyen

www.kblaa.com
EnergyUnited StatesJul 7 · 17:30 UTC

United Infrastructure

www.unitedinfrastructure.com