The Federal Bureau of Investigation (FBI), in partnership with the Cybersecurity and Infrastructure Security Agency (CISA) and Australia’s ASD’s ACSC.
It has released a comprehensive technical advisory detailing the Tactics, Techniques, and Procedures (TTPs) along with Indicators of Compromise (IoCs) associated with the Play ransomware group a threat collective responsible for compromising over 900 organizations across North America, South America, and Europe as of May 2025.
First identified in June 2022 and exhibiting heightened activity throughout 2024, Play (also tracked as Playcrypt) ransomware has become one of the most prolific cyber extortion groups in recent years.
Notably, the group employs a double extortion model, exfiltrating sensitive data before encrypting victims’ systems, and subsequently threatening public data release if their demands are not met.
The group’s operational secrecy is maintained via closed communication channels victims are instructed to contact unique @gmx.de or @web.de addresses, and in some cases, are even phoned and threatened to expedite payment.
Technical Attack Chain and TTPs
Play ransomware’s initial access typically leverages valid account abuse (often via credentials purchased on the dark web) and exploitation of public-facing applications.
High-profile vulnerabilities targeted include FortiOS (CVE-2018-13379, CVE-2020-12812) and Microsoft Exchange (ProxyNotShell: CVE-2022-41040, CVE-2022-41082).
Recent attacks have also exploited CVE-2024-57727 in the SimpleHelp remote monitoring tool, with attackers using RDP and VPN for network entry.
Upon access, Play actors conduct discovery using utilities like AdFind and Grixba for Active Directory reconnaissance and anti-virus detection.
For defense evasion, tools such as GMER, IOBit, and PowerTool are deployed to disable endpoint protection and clear event logs.
Lateral movement is facilitated through Cobalt Strike, SystemBC, and PsExec, with credential escalation via Mimikatz and privilege enumeration by WinPEAS.
According to the Report, Data exfiltration is performed using WinRAR for data compression and WinSCP for transfer to attacker-controlled infrastructure.
Encryption utilizes an AES-RSA hybrid technique, appending a .PLAY extension and skipping system files to ensure operational impact while maintaining ransom leverage.
Specific Tactics
Beyond Windows environments, Play ransomware’s ESXi variant employs custom shell commands, powers down virtual machines, and encrypts VMware-related files with AES-256.
Each deployment is uniquely recompiled to evade signature-based detection, further complicating incident response.
The ESXi variant supports campaign-specific flags and places ransom notes both in system directories and as ESXi welcome messages, underscoring the group’s technical sophistication.
The FBI, CISA, and ACSC strongly urge organizations to implement multifactor authentication, prioritize patching of known exploited vulnerabilities, maintain segmented and regularly backed-up infrastructure, and strengthen password policies.
Detection should focus on anomalous use of legitimate tools (e.g., PsExec, Cobalt Strike, AdFind), unauthorized data compression or transfer activity, and custom binaries with IoCs outlined below.
Indicators of Compromise (IoCs)
| Hash (SHA256/SHA1) | Description |
|---|---|
| 47B7B2DD88959CD7224A5542AE8D5BCE928BFC986BF0D0321532A7515C244A1E | SVCHost.dll (Backdoor) |
| 75B525B220169F07AECFB3B1991702FBD9A1E170CAF0040D1FCB07C3E819F54A | GRIXBA / Gt_net.exe (Data Gathering Tool) |
| C59F3C8D61D940B56436C14BC148C1FE98862921B8F7BAD97FBC96B31D71193C | GRIXBA / Gt_net.exe (Data Gathering Tool) |
| 1409E010675BF4A40DB0A845B60DB3AAE5B302834E80ADEEC884AEBC55ECCBF7 | PSexesvc.exe (Custom PsExec) |
| 0E408AED1ACF902A9F97ABF71CF0DD354024109C5D52A79054C421BE35D93549 | HRsword.exe (Disables Endpoint Protection) |
| 90040340EE101CAC7831D7035230AC8AD4224D432E5636F34F13AA1C4A0C2041 | Usysdiag.exe (System Certificates) |
| 6DE8DD5757F9A3AC5E2AC28E8A77682D7A29BE25C106F785A061DCF582A20DC6 | Hi.exe (Associated with Ransomware) |
| 75404543DE25513B376F097CEB383E8EFB9C9B95DA8945FD4AA37C7B2F226212 | SystemBC Malware EXE |
| 7DEA671BE77A2CA5772B86CF8831B02BFF0567BCE6A3AE023825AA40354F8ACA | SystemBC Malware DLL |
| 859165041D75FBA3759C5533E324225F355C8A07B4645B984192AD6BEF06DB1A | Public ED25519 Key (WinSCP Server) |
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Update