StopRansomware: Play Ransomware
June 5, 2025, 1:46 p.m.
Description
The Play ransomware group has been actively targeting businesses and critical infrastructure across North America, South America, and Europe since June 2022. They gain initial access through exploiting vulnerabilities, using stolen credentials, and leveraging remote access services. The group employs a double extortion model, encrypting systems after data exfiltration. Play ransomware uses AES-RSA hybrid encryption and intermittent encryption techniques. The actors use various tools for network discovery, credential theft, and lateral movement. Organizations are advised to implement robust security measures including multifactor authentication, regular patching, network segmentation, and maintaining offline backups to mitigate the risk of ransomware attacks.
Tags
Date
- Created: June 5, 2025, 1:24 p.m.
- Published: June 5, 2025, 1:24 p.m.
- Modified: June 5, 2025, 1:46 p.m.
Indicators
- 0e408aed1acf902a9f97abf71cf0dd354024109c5d52a79054c421be35d93549
- 75b525b220169f07aecfb3b1991702fbd9a1e170caf0040d1fcb07c3e819f54a
- 47b7b2dd88959cd7224a5542ae8d5bce928bfc986bf0d0321532a7515c244a1e
- 7dea671be77a2ca5772b86cf8831b02bff0567bce6a3ae023825aa40354f8aca
- 7a42f96599df8090cf89d6e3ce4316d24c6c00e499c8557a2e09d61c00c11986
- 75404543de25513b376f097ceb383e8efb9c9b95da8945fd4aa37c7b2f226212
- c59f3c8d61d940b56436c14bc148c1fe98862921b8f7bad97fbc96b31d71193c
- 453257c3494addafb39cb6815862403e827947a1e7737eb8168cd10522465deb
Attack Patterns
- Grixba
- Play
- SystemBC
- Play
Additional Informations
- Critical Infrastructure
- Australia
- United States of America