About this actor
Initially observed in June 2022, the Play ransomware (a.k.a PlayCrypt) operates through double extortion, targeting numerous organizations in Latin America. Its Initial Access method is quite similar to other ransomwares, involving attacks such as Phishing, Exposed Services to the Internet, and Valid Account compromises. On April 19, 2023, the security company Symantec published two new tools developed by the Play group. These tools allow the malicious actor to enumerate and exfiltrate data from the internal network. The post mentions the following: "Play threat actors use the .NET infostealer to enumerate software and services via WMI, WinRM, Remote Registry, and Remote Service. The malware checks for the existence of security and backup software, as well as remote administration tools and other programs, saving the information in .CSV files that are compressed into a .ZIP file for later manual exfiltration by threat actors." These tools make use of the following .NET frameworks (Costura, AlphaVSS).
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 35 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
No activity events recorded.
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
| No attributed CVEs. | |||||
T1003OS Credential Dumping ↗T1003.001LSASS Memory ↗T1016System Network Configuration Discovery ↗T1018Remote System Discovery ↗T1021Remote Services ↗T1021.002SMB/Windows Admin Shares ↗T1027Obfuscated Files or Information ↗T1027.010Command Obfuscation ↗T1030Data Transfer Size Limits ↗T1048Exfiltration Over Alternative Protocol ↗T1057Process Discovery ↗T1059Command and Scripting Interpreter ↗T1059.001PowerShell ↗T1059.003Windows Command Shell ↗T1070Indicator Removal ↗T1070.004File Deletion ↗T1078Valid Accounts ↗T1078.002Domain Accounts ↗T1078.003Local Accounts ↗T1082System Information Discovery ↗T1083File and Directory Discovery ↗T1105Ingress Tool Transfer ↗T1133External Remote Services ↗T1190Exploit Public-Facing Application ↗T1518Software Discovery ↗T1518.001Security Software Discovery ↗T1560Archive Collected Data ↗T1560.001Archive via Utility ↗T1587Develop Capabilities ↗T1587.001Malware ↗T1588Obtain Capabilities ↗T1588.002Tool ↗T1657Financial Theft ↗T1685Disable or Modify Tools ↗T1685.005Clear Windows Event Logs ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-4 | 22 / 35 | 63% |
CM-6 | 20 / 35 | 57% |
AC-3 | 17 / 35 | 49% |
AC-6 | 17 / 35 | 49% |
CM-2 | 17 / 35 | 49% |
SI-3 | 16 / 35 | 46% |
AC-2 | 15 / 35 | 43% |
AC-5 | 14 / 35 | 40% |
CA-7 | 13 / 35 | 37% |
CM-7 | 12 / 35 | 34% |
IA-2 | 12 / 35 | 34% |
CM-5 | 11 / 35 | 31% |
SI-7 | 10 / 35 | 29% |
SC-7 | 9 / 35 | 26% |
AC-17 | 8 / 35 | 23% |
Co-occurring actors
None.
Similar actors
Similar TTPs
- FIN8 0.38
- Aquatic Panda 0.38
- Operation Wocao 0.33
- MirrorFace 0.32
- Cutting Edge 0.31
Same category
- LAPSUS$ 1.00
- Akira 1.00
- INC Ransom 1.00
- BlackByte 1.00
- ShinyHunters 1.00