play
Initially observed in June 2022, the Play ransomware (a.k.a PlayCrypt) operates through double extortion, targeting numerous organizations in Latin America. Its Initial Access method is quite similar to other ransomwares, involving attacks such as Phishing, Exposed Services to the Internet, and Valid Account compromises. On April 19, 2023, the security company Symantec published two new tools developed by the Play group. These tools allow the malicious actor to enumerate and exfiltrate data from the internal network. The post mentions the following: 'Play threat actors use the .NET infostealer to enumerate software and services via WMI, WinRM, Remote Registry, and Remote Service. The malware checks for the existence of security and backup software, as well as remote administration tools and other programs, saving the information in .CSV files that are compressed into a .ZIP file for later manual exfiltration by threat actors.'Source: https://github.com/crocodyli/ThreatActors-TTPs
- Unspecified
- Technology
- Manufacturing
- Business Services
- Professional Services
- Financial Services
- Consumer Services
- Telecommunication
- TA0001Initial Access
- T1078Valid Accounts
Compromised VPN credentials used to authenticate directly to victim networks.
- T1078.002Valid Accounts: Domain Accounts
[Play](https://attack.mitre.org/groups/G1040) has used valid domain accounts for access.(Citation: Trend Micro Ransomware Spotlight Play July 2023)
- T1078.003Valid Accounts: Local Accounts
[Play](https://attack.mitre.org/groups/G1040) has used valid local accounts to gain initial access.(Citation: Trend Micro Ransomware Spotlight Play July 2023)
- T1133External Remote Services
[Play](https://attack.mitre.org/groups/G1040) has used Remote Desktop Protocol (RDP) and Virtual Private Networks (VPN) for initial access.(Citation: CISA Play Ransomware Advisory December 2023)(Citation: Trend Micro Ransomware Spotlight Play July 2023)
- T1190Exploit Public-Facing Application
Play exploits vulnerabilities in Microsoft Exchange (ProxyNotShell CVE-2022-41040/CVE-2022-41082), FortiOS SSL VPN (CVE-2018-13379), and RDP to gain initial access.
- TA0002Execution
- T1053.005Scheduled Task/Job: Scheduled Task
Scheduled tasks used for payload persistence and execution across compromised hosts.
- T1059Command and Scripting Interpreter
- T1059.001Command and Scripting Interpreter: PowerShell
PowerShell scripts used for payload execution and post-exploitation tooling deployment.
- T1059.003Command and Scripting Interpreter: Windows Command Shell
[Play](https://attack.mitre.org/groups/G1040) has used a batch script to remove indicators of its presence on compromised hosts.(Citation: Trend Micro Ransomware Spotlight Play July 2023)
- TA0003Persistence
- T1078.002Valid Accounts: Domain Accounts
[Play](https://attack.mitre.org/groups/G1040) has used valid domain accounts for access.(Citation: Trend Micro Ransomware Spotlight Play July 2023)
- T1078.003Valid Accounts: Local Accounts
[Play](https://attack.mitre.org/groups/G1040) has used valid local accounts to gain initial access.(Citation: Trend Micro Ransomware Spotlight Play July 2023)
- T1133External Remote Services
[Play](https://attack.mitre.org/groups/G1040) has used Remote Desktop Protocol (RDP) and Virtual Private Networks (VPN) for initial access.(Citation: CISA Play Ransomware Advisory December 2023)(Citation: Trend Micro Ransomware Spotlight Play July 2023)
- TA0004Privilege Escalation
- T1078.002Valid Accounts: Domain Accounts
[Play](https://attack.mitre.org/groups/G1040) has used valid domain accounts for access.(Citation: Trend Micro Ransomware Spotlight Play July 2023)
- T1078.003Valid Accounts: Local Accounts
[Play](https://attack.mitre.org/groups/G1040) has used valid local accounts to gain initial access.(Citation: Trend Micro Ransomware Spotlight Play July 2023)
- TA0005Defense Evasion
- T1027Obfuscated Files or Information
Play ransomware payloads are split into multiple parts to bypass AV scanning; parts reassembled on target systems.
- T1070Indicator Removal
- T1070.001Indicator Removal: Clear Windows Event Logs
Windows event logs wiped to remove forensic evidence using wevtutil.
- T1484Domain or Tenant Policy Modification
- T1484.001Domain or Tenant Policy Modification: Group Policy Modification
- T1562.001Disable or Modify Tools
Security tools including Windows Defender and AV products disabled prior to encryption.
- TA0005Stealth
- T1027.010Obfuscated Files or Information: Command Obfuscation
[Play](https://attack.mitre.org/groups/G1040) has used Base64-encoded PowerShell scripts for post exploit activities on compromised hosts.(Citation: Trend Micro Ransomware Spotlight Play July 2023)
- T1070.004Indicator Removal: File Deletion
[Play](https://attack.mitre.org/groups/G1040) has used tools including [Wevtutil](https://attack.mitre.org/software/S0645) to remove malicious files from compromised hosts.(Citation: Trend Micro Ransomware Spotlight Play July 2023)
- T1078.002Valid Accounts: Domain Accounts
[Play](https://attack.mitre.org/groups/G1040) has used valid domain accounts for access.(Citation: Trend Micro Ransomware Spotlight Play July 2023)
- T1078.003Valid Accounts: Local Accounts
[Play](https://attack.mitre.org/groups/G1040) has used valid local accounts to gain initial access.(Citation: Trend Micro Ransomware Spotlight Play July 2023)
- TA0006Credential Access
- TA0007Discovery
- T1016System Network Configuration Discovery
- T1018Remote System Discovery
[Play](https://attack.mitre.org/groups/G1040) has used tools such as [AdFind](https://attack.mitre.org/software/S0552), [Nltest](https://attack.mitre.org/software/S0359), and [BloodHound](https://attack.mitre.org/software/S0521) to enumerate shares and hostnames on compromised networks.(Citation: Trend Micro Ransomware Spotlight Play July 2023)
- T1046Network Service Discovery
Network scanning tools used to enumerate hosts, services, and potential lateral movement targets.
- T1057Process Discovery
[Play](https://attack.mitre.org/groups/G1040) has used the information stealer Grixba to check for a list of security processes.(Citation: Trend Micro Ransomware Spotlight Play July 2023)
- T1082System Information Discovery
[Play](https://attack.mitre.org/groups/G1040) has leveraged tools to enumerate system information.(Citation: Trend Micro Ransomware Spotlight Play July 2023)
- T1083File and Directory Discovery
[Play](https://attack.mitre.org/groups/G1040) has used the Grixba information stealer to list security files and processes.(Citation: Trend Micro Ransomware Spotlight Play July 2023)
- T1087.002Account Discovery: Domain Account
Active Directory enumeration to identify privileged accounts and high-value targets.
- T1518Software Discovery
- T1518.001Software Discovery: Security Software Discovery
- TA0008Lateral Movement
- TA0009Collection
- TA0010Exfiltration
- T1030Data Transfer Size Limits
[Play](https://attack.mitre.org/groups/G1040) has split victims' files into chunks for exfiltration.(Citation: CISA Play Ransomware Advisory December 2023)(Citation: Trend Micro Ransomware Spotlight Play July 2023)
- T1048Exfiltration Over Alternative Protocol
WinSCP and Rclone used to exfiltrate data to actor-controlled infrastructure and cloud storage ahead of encryption.
- TA0011Command and Control
- T1105Ingress Tool Transfer
[Play](https://attack.mitre.org/groups/G1040) has used [Cobalt Strike](https://attack.mitre.org/software/S0154) to download files to compromised machines.(Citation: Trend Micro Ransomware Spotlight Play July 2023)
- T1219Remote Access Software
Cobalt Strike, SystemBC, and AnyDesk used as C2 frameworks for persistent access.
- TA0040Impact
- T1486Data Encrypted for Impact
Play ransomware uses AES-RSA hybrid encryption. Files appended with .play extension. Targets Windows and Linux/ESXi environments. Double extortion model with data published on Play leak site. Notable for NOT including ransom note in individual encrypted files — single note left at root of C: drive.
- T1489Service Stop
Database, mail, backup, and security services terminated before encryption to ensure maximum file access.
- T1490Inhibit System Recovery
Shadow copies deleted and Windows recovery disabled to prevent victim restoration of files.
- T1657Financial Theft
- TA0042Resource Development
- T1587.001Develop Capabilities: Malware
[Play](https://attack.mitre.org/groups/G1040) developed and employ [Playcrypt](https://attack.mitre.org/software/S1162) ransomware.(Citation: Trend Micro Ransomware Spotlight Play July 2023)(Citation: CISA Play Ransomware Advisory December 2023)
- T1588.002Obtain Capabilities: Tool
[Play](https://attack.mitre.org/groups/G1040) has used multiple tools for discovery and defense evasion purposes on compromised hosts.(Citation: CISA Play Ransomware Advisory December 2023)
- TA0112Defense Impairment
- T1685Disable or Modify Tools
[Play](https://attack.mitre.org/groups/G1040) has used tools including GMER, IOBit, and PowerTool to disable antivirus software.(Citation: CISA Play Ransomware Advisory December 2023)(Citation: Trend Micro Ransomware Spotlight Play July 2023)
- T1685.005Disable or Modify Tools: Clear Windows Event Logs
[Play](https://attack.mitre.org/groups/G1040) has used tools to remove log files on targeted systems.(Citation: CISA Play Ransomware Advisory December 2023)(Citation: Trend Micro Ransomware Spotlight Play July 2023)