ATT&CKReferencesTrend Micro Ransomware Spotlight Play July 2023

Trend Micro Ransomware Spotlight Play July 2023

Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples24

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupPlay

Play has used Mimikatz and the Windows Task Manager to dump LSASS process memory.

T1018
Remote System Discovery
GroupPlay

Play has used tools such as AdFind, Nltest, and BloodHound to enumerate shares and hostnames on compromised networks.

T1021.002
SMB/Windows Admin Shares
GroupPlay

Play has used Cobalt Strike to move laterally via SMB.

T1027.010
Command Obfuscation
GroupPlay

Play has used Base64-encoded PowerShell scripts for post exploit activities on compromised hosts.

T1030
Data Transfer Size Limits
GroupPlay

Play has split victims' files into chunks for exfiltration.

T1048
Exfiltration Over Alternative Protocol
GroupPlay

Play has used WinSCP to exfiltrate data to actor-controlled accounts.

T1057
Process Discovery
GroupPlay

Play has used the information stealer Grixba to check for a list of security processes.

T1059.001
PowerShell
GroupPlay

Play has used Base64-encoded PowerShell scripts to disable Microsoft Defender.

T1059.003
Windows Command Shell
GroupPlay

Play has used a batch script to remove indicators of its presence on compromised hosts.

T1070.004
File Deletion
GroupPlay

Play has used tools including Wevtutil to remove malicious files from compromised hosts.

T1078.002
Domain Accounts
GroupPlay

Play has used valid domain accounts for access.

T1078.003
Local Accounts
GroupPlay

Play has used valid local accounts to gain initial access.

T1082
System Information Discovery
GroupPlay

Play has leveraged tools to enumerate system information.

T1083
File and Directory Discovery
GroupPlay

Play has used the Grixba information stealer to list security files and processes.

T1083
File and Directory Discovery
MalwarePlaycrypt

Playcrypt can avoid encrypting files with a .PLAY, .exe, .msi, .dll, .lnk, or .sys file extension.

T1105
Ingress Tool Transfer
GroupPlay

Play has used Cobalt Strike to download files to compromised machines.

T1133
External Remote Services
GroupPlay

Play has used Remote Desktop Protocol (RDP) and Virtual Private Networks (VPN) for initial access.

T1190
Exploit Public-Facing Application
GroupPlay

Play has exploited known vulnerabilities for initial access including CVE-2018-13379 and CVE-2020-12812 in FortiOS and CVE-2022-41082 and CVE-2022-41040 ("ProxyNotShell") in Microsoft Exchange.

T1486
Data Encrypted for Impact
MalwarePlaycrypt

Playcrypt encrypts files on targeted hosts with an AES-RSA hybrid encryption, encrypting every other file portion of 0x100000 bytes.

T1490
Inhibit System Recovery
MalwarePlaycrypt

Playcrypt can use AlphaVSS to delete shadow copies.

T1560.001
Archive via Utility
GroupPlay

Play has used WinRAR to compress files prior to exfiltration.

T1587.001
Malware
GroupPlay

Play developed and employ Playcrypt ransomware.

T1685
Disable or Modify Tools
GroupPlay

Play has used tools including GMER, IOBit, and PowerTool to disable antivirus software.

T1685.005
Clear Windows Event Logs
GroupPlay

Play has used tools to remove log files on targeted systems.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.