Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupPlay | Play has used Mimikatz and the Windows Task Manager to dump LSASS process memory. |
| T1018 Remote System Discovery |
GroupPlay | Play has used tools such as AdFind, Nltest, and BloodHound to enumerate shares and hostnames on compromised networks. |
| T1021.002 SMB/Windows Admin Shares |
GroupPlay | Play has used Cobalt Strike to move laterally via SMB. |
| T1027.010 Command Obfuscation |
GroupPlay | Play has used Base64-encoded PowerShell scripts for post exploit activities on compromised hosts. |
| T1030 Data Transfer Size Limits |
GroupPlay | Play has split victims' files into chunks for exfiltration. |
| T1048 Exfiltration Over Alternative Protocol |
GroupPlay | Play has used WinSCP to exfiltrate data to actor-controlled accounts. |
| T1057 Process Discovery |
GroupPlay | Play has used the information stealer Grixba to check for a list of security processes. |
| T1059.001 PowerShell |
GroupPlay | Play has used Base64-encoded PowerShell scripts to disable Microsoft Defender. |
| T1059.003 Windows Command Shell |
GroupPlay | Play has used a batch script to remove indicators of its presence on compromised hosts. |
| T1070.004 File Deletion |
GroupPlay | Play has used tools including Wevtutil to remove malicious files from compromised hosts. |
| T1078.002 Domain Accounts |
GroupPlay | Play has used valid domain accounts for access. |
| T1078.003 Local Accounts |
GroupPlay | Play has used valid local accounts to gain initial access. |
| T1082 System Information Discovery |
GroupPlay | Play has leveraged tools to enumerate system information. |
| T1083 File and Directory Discovery |
GroupPlay | Play has used the Grixba information stealer to list security files and processes. |
| T1083 File and Directory Discovery |
MalwarePlaycrypt | Playcrypt can avoid encrypting files with a .PLAY, .exe, .msi, .dll, .lnk, or .sys file extension. |
| T1105 Ingress Tool Transfer |
GroupPlay | Play has used Cobalt Strike to download files to compromised machines. |
| T1133 External Remote Services |
GroupPlay | Play has used Remote Desktop Protocol (RDP) and Virtual Private Networks (VPN) for initial access. |
| T1190 Exploit Public-Facing Application |
GroupPlay | Play has exploited known vulnerabilities for initial access including CVE-2018-13379 and CVE-2020-12812 in FortiOS and CVE-2022-41082 and CVE-2022-41040 ("ProxyNotShell") in Microsoft Exchange. |
| T1486 Data Encrypted for Impact |
MalwarePlaycrypt | Playcrypt encrypts files on targeted hosts with an AES-RSA hybrid encryption, encrypting every other file portion of 0x100000 bytes. |
| T1490 Inhibit System Recovery |
MalwarePlaycrypt | Playcrypt can use AlphaVSS to delete shadow copies. |
| T1560.001 Archive via Utility |
GroupPlay | Play has used WinRAR to compress files prior to exfiltration. |
| T1587.001 Malware |
GroupPlay | |
| T1685 Disable or Modify Tools |
GroupPlay | Play has used tools including GMER, IOBit, and PowerTool to disable antivirus software. |
| T1685.005 Clear Windows Event Logs |
GroupPlay | Play has used tools to remove log files on targeted systems. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.