Sophos X-Ops · @SophosXOps
1293 followers · 113 posts · Server infosec.exchange

New bullies on the block: They don’t PLAY nice.

In mid-November 2022, X-Ops responded to an incident where PLAY , also known as , was found in an under-protected environment.

PLAY is a relatively new ransomware variant, first reported in mid-July of 2022. It deploys a variety of commonly abused tools, similar to other Ransomware-as-a-Service (RaaS) deployments such as Hive or Nokoyawa. In this thread we’ll walk through what Sophos X-Ops researchers @bencrypted and @th3_protoCOL saw in their analysis – a process our Rapid Response team observed in reverse, starting their work with this customer when they were called in at the 14-day mark.

The IoCs provided in this writeup are available on our Github: github.com/sophoslabs/IoCs.

#sophos #ransomware #playcrypt #threatintel #infosec #ioc #sophosxops

Last updated 2 years ago

I've had a look at , aka . And it seems to me that there is more than meets the eye when it comes to negotiations management. At first, it looks like "just" e-mail. But I suspect there's more to it than just that. More about it in this piece (sorry, it's in French): lemagit.fr/actualites/25252779

#play #playcrypt #ransomware

Last updated 2 years ago