CISA. (2023, December 18). #StopRansomware: Play Ransomware AA23-352A. Retrieved September 24, 2024.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
GroupPlay | Play has used the information-stealing tool Grixba to enumerate network information. |
| T1030 Data Transfer Size Limits |
GroupPlay | Play has split victims' files into chunks for exfiltration. |
| T1048 Exfiltration Over Alternative Protocol |
GroupPlay | Play has used WinSCP to exfiltrate data to actor-controlled accounts. |
| T1078 Valid Accounts |
GroupPlay | Play has used valid VPN accounts to achieve initial access. |
| T1133 External Remote Services |
GroupPlay | Play has used Remote Desktop Protocol (RDP) and Virtual Private Networks (VPN) for initial access. |
| T1190 Exploit Public-Facing Application |
GroupPlay | Play has exploited known vulnerabilities for initial access including CVE-2018-13379 and CVE-2020-12812 in FortiOS and CVE-2022-41082 and CVE-2022-41040 ("ProxyNotShell") in Microsoft Exchange. |
| T1486 Data Encrypted for Impact |
MalwarePlaycrypt | Playcrypt encrypts files on targeted hosts with an AES-RSA hybrid encryption, encrypting every other file portion of 0x100000 bytes. |
| T1518.001 Security Software Discovery |
GroupPlay | Play has used the information-stealing tool Grixba to scan for anti-virus software. |
| T1560.001 Archive via Utility |
GroupPlay | Play has used WinRAR to compress files prior to exfiltration. |
| T1587.001 Malware |
GroupPlay | |
| T1588.002 Tool |
GroupPlay | Play has used multiple tools for discovery and defense evasion purposes on compromised hosts. |
| T1657 Financial Theft |
GroupPlay | Play demands ransom payments from victims to unencrypt filesystems and to not publish sensitive data exfiltrated from victim networks. |
| T1685 Disable or Modify Tools |
GroupPlay | Play has used tools including GMER, IOBit, and PowerTool to disable antivirus software. |
| T1685.005 Clear Windows Event Logs |
GroupPlay | Play has used tools to remove log files on targeted systems. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.