ATT&CKReferencesCISA Play Ransomware Advisory December 2023

CISA Play Ransomware Advisory December 2023

CISA. (2023, December 18). #StopRansomware: Play Ransomware AA23-352A. Retrieved September 24, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
GroupPlay

Play has used the information-stealing tool Grixba to enumerate network information.

T1030
Data Transfer Size Limits
GroupPlay

Play has split victims' files into chunks for exfiltration.

T1048
Exfiltration Over Alternative Protocol
GroupPlay

Play has used WinSCP to exfiltrate data to actor-controlled accounts.

T1078
Valid Accounts
GroupPlay

Play has used valid VPN accounts to achieve initial access.

T1133
External Remote Services
GroupPlay

Play has used Remote Desktop Protocol (RDP) and Virtual Private Networks (VPN) for initial access.

T1190
Exploit Public-Facing Application
GroupPlay

Play has exploited known vulnerabilities for initial access including CVE-2018-13379 and CVE-2020-12812 in FortiOS and CVE-2022-41082 and CVE-2022-41040 ("ProxyNotShell") in Microsoft Exchange.

T1486
Data Encrypted for Impact
MalwarePlaycrypt

Playcrypt encrypts files on targeted hosts with an AES-RSA hybrid encryption, encrypting every other file portion of 0x100000 bytes.

T1518.001
Security Software Discovery
GroupPlay

Play has used the information-stealing tool Grixba to scan for anti-virus software.

T1560.001
Archive via Utility
GroupPlay

Play has used WinRAR to compress files prior to exfiltration.

T1587.001
Malware
GroupPlay

Play developed and employ Playcrypt ransomware.

T1588.002
Tool
GroupPlay

Play has used multiple tools for discovery and defense evasion purposes on compromised hosts.

T1657
Financial Theft
GroupPlay

Play demands ransom payments from victims to unencrypt filesystems and to not publish sensitive data exfiltrated from victim networks.

T1685
Disable or Modify Tools
GroupPlay

Play has used tools including GMER, IOBit, and PowerTool to disable antivirus software.

T1685.005
Clear Windows Event Logs
GroupPlay

Play has used tools to remove log files on targeted systems.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.