FBI Released TTPs & IoCs Play Ransomware That Compromise 900+ Organizations

The Federal Bureau of Investigation (FBI), in partnership with the Cybersecurity and Infrastructure Security Agency (CISA) and Australia’s ASD’s ACSC.

It has released a comprehensive technical advisory detailing the Tactics, Techniques, and Procedures (TTPs) along with Indicators of Compromise (IoCs) associated with the Play ransomware group a threat collective responsible for compromising over 900 organizations across North America, South America, and Europe as of May 2025.

First identified in June 2022 and exhibiting heightened activity throughout 2024, Play (also tracked as Playcrypt) ransomware has become one of the most prolific cyber extortion groups in recent years.

Notably, the group employs a double extortion model, exfiltrating sensitive data before encrypting victims’ systems, and subsequently threatening public data release if their demands are not met.

The group’s operational secrecy is maintained via closed communication channels victims are instructed to contact unique @gmx.de or @web.de addresses, and in some cases, are even phoned and threatened to expedite payment.

Technical Attack Chain and TTPs

Play ransomware’s initial access typically leverages valid account abuse (often via credentials purchased on the dark web) and exploitation of public-facing applications.

High-profile vulnerabilities targeted include FortiOS (CVE-2018-13379, CVE-2020-12812) and Microsoft Exchange (ProxyNotShell: CVE-2022-41040, CVE-2022-41082).

Recent attacks have also exploited CVE-2024-57727 in the SimpleHelp remote monitoring tool, with attackers using RDP and VPN for network entry.

Upon access, Play actors conduct discovery using utilities like AdFind and Grixba for Active Directory reconnaissance and anti-virus detection.

For defense evasion, tools such as GMER, IOBit, and PowerTool are deployed to disable endpoint protection and clear event logs.

Lateral movement is facilitated through Cobalt Strike, SystemBC, and PsExec, with credential escalation via Mimikatz and privilege enumeration by WinPEAS.

According to the Report, Data exfiltration is performed using WinRAR for data compression and WinSCP for transfer to attacker-controlled infrastructure.

Encryption utilizes an AES-RSA hybrid technique, appending a .PLAY extension and skipping system files to ensure operational impact while maintaining ransom leverage.

Specific Tactics

Beyond Windows environments, Play ransomware’s ESXi variant employs custom shell commands, powers down virtual machines, and encrypts VMware-related files with AES-256.

Each deployment is uniquely recompiled to evade signature-based detection, further complicating incident response.

The ESXi variant supports campaign-specific flags and places ransom notes both in system directories and as ESXi welcome messages, underscoring the group’s technical sophistication.

The FBI, CISA, and ACSC strongly urge organizations to implement multifactor authentication, prioritize patching of known exploited vulnerabilities, maintain segmented and regularly backed-up infrastructure, and strengthen password policies.

Detection should focus on anomalous use of legitimate tools (e.g., PsExec, Cobalt Strike, AdFind), unauthorized data compression or transfer activity, and custom binaries with IoCs outlined below.

Indicators of Compromise (IoCs)

Hash (SHA256/SHA1)Description
47B7B2DD88959CD7224A5542AE8D5BCE928BFC986BF0D0321532A7515C244A1ESVCHost.dll (Backdoor)
75B525B220169F07AECFB3B1991702FBD9A1E170CAF0040D1FCB07C3E819F54AGRIXBA / Gt_net.exe (Data Gathering Tool)
C59F3C8D61D940B56436C14BC148C1FE98862921B8F7BAD97FBC96B31D71193CGRIXBA / Gt_net.exe (Data Gathering Tool)
1409E010675BF4A40DB0A845B60DB3AAE5B302834E80ADEEC884AEBC55ECCBF7PSexesvc.exe (Custom PsExec)
0E408AED1ACF902A9F97ABF71CF0DD354024109C5D52A79054C421BE35D93549HRsword.exe (Disables Endpoint Protection)
90040340EE101CAC7831D7035230AC8AD4224D432E5636F34F13AA1C4A0C2041Usysdiag.exe (System Certificates)
6DE8DD5757F9A3AC5E2AC28E8A77682D7A29BE25C106F785A061DCF582A20DC6Hi.exe (Associated with Ransomware)
75404543DE25513B376F097CEB383E8EFB9C9B95DA8945FD4AA37C7B2F226212SystemBC Malware EXE
7DEA671BE77A2CA5772B86CF8831B02BFF0567BCE6A3AE023825AA40354F8ACASystemBC Malware DLL
859165041D75FBA3759C5533E324225F355C8A07B4645B984192AD6BEF06DB1APublic ED25519 Key (WinSCP Server)

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Update

Mandvi
Mandvi
Mandvi is a Security Reporter covering data breaches, malware, cyberattacks, data leaks, and more at Cyber Press.

Trending News

Related Stories