Play

G1040

Threat group.View on attack.mitre.org

About this group

Play is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a double-extortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.

Techniques used26

Procedure examples26

TechniqueProcedure example
T1003.001
LSASS Memory

Play has used Mimikatz and the Windows Task Manager to dump LSASS process memory.

T1016
System Network Configuration Discovery

Play has used the information-stealing tool Grixba to enumerate network information.

T1018
Remote System Discovery

Play has used tools such as AdFind, Nltest, and BloodHound to enumerate shares and hostnames on compromised networks.

T1021.002
SMB/Windows Admin Shares

Play has used Cobalt Strike to move laterally via SMB.

T1027.010
Command Obfuscation

Play has used Base64-encoded PowerShell scripts for post exploit activities on compromised hosts.

T1030
Data Transfer Size Limits

Play has split victims' files into chunks for exfiltration.

T1048
Exfiltration Over Alternative Protocol

Play has used WinSCP to exfiltrate data to actor-controlled accounts.

T1057
Process Discovery

Play has used the information stealer Grixba to check for a list of security processes.

T1059.001
PowerShell

Play has used Base64-encoded PowerShell scripts to disable Microsoft Defender.

T1059.003
Windows Command Shell

Play has used a batch script to remove indicators of its presence on compromised hosts.

T1070.004
File Deletion

Play has used tools including Wevtutil to remove malicious files from compromised hosts.

T1078
Valid Accounts

Play has used valid VPN accounts to achieve initial access.

T1078.002
Domain Accounts

Play has used valid domain accounts for access.

T1078.003
Local Accounts

Play has used valid local accounts to gain initial access.

T1082
System Information Discovery

Play has leveraged tools to enumerate system information.

View all 26 procedure examples

Software9

Campaigns0

None recorded.

References2

  1. CISA Play Ransomware Advisory December 2023 Open source
    CISA. (2023, December 18). #StopRansomware: Play Ransomware AA23-352A. Retrieved September 24, 2024.
  2. Trend Micro Ransomware Spotlight Play July 2023 Open source
    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.