Threat Advisory

Play Ransomware Group Using New Custom Data-Gathering Tools

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

The Balloonfly-developed Play ransomware, also known as PlayCrypt, was first released in June 2022 and has since been used in several high-profile attacks. The play employs double-extortion attacks, in which the attackers steal data from victim networks before encrypting them. The ransomware group initially targeted businesses in Latin America, particularly Brazil, but gradually expanded its scope. In addition, the gang was one of the first ransomware groups to use intermittent encryption, which speeds up the encryption of victims' devices.[/subscribe_to_unlock_form]

Summary:

The Balloonfly-developed Play ransomware, also known as PlayCrypt, was first released in June 2022 and has since been used in several high-profile attacks. The play employs double-extortion attacks, in which the attackers steal data from victim networks before encrypting them. The ransomware group initially targeted businesses in Latin America, particularly Brazil, but gradually expanded its scope. In addition, the gang was one of the first ransomware groups to use intermittent encryption, which speeds up the encryption of victims' devices.[emaillocker id="1283"]

The Play ransomware group has created two new, specially designed tools that allow it to list all computers and users on a compromised network and copy files from the Volume Shadow Copy Service (VSS) that are typically locked by the operating system. The first tool discovered by the researchers was Grixba a network-scanning tool used to list all users and computers in the domain. Through WMI, WinRM, Remote Registry, and Remote Services, the threat actors use the .NET infostealer to enumerate software and services. The malware scans for the presence of backup and security software as well as remote administration tools and other programmes, saving the obtained data in CSV files that are compressed into a ZIP file for manual exfiltration by threat actors later. Using Costura, a well-liked.NET development tool the Play ransomware gang created Grixba. It is then easy to distribute and deploy the application because there is no longer a requirement for the software and its dependencies to be delivered separately. Grixba uses the DLL file that Costura embeds into applications to parse command lines.

Another .NET executable that was likewise created utilizing the Costura tool was recently seen being used by the Play ransomware gang. AlphaVSS is a library that Costura integrates into executables. A .NET framework called the AlphaVSS library offers a high-level interface for interfacing with VSS.  AlphaVSS is used by the Play ransomware groups to copy files from VSS snapshots. The utility copies the files and folders in a VSS snapshot to a destination directory after listing each one. Using the tool, attackers can copy files from VSS drives on infected devices before they are encrypted.

Ransomware groups are increasingly employing custom tools in their operations. Ransomware gangs may launch attacks more quickly and effectively by using custom tools that can be adjusted to a particular target environment. If a tool is widely used, additional attackers may reverse-engineer it or adapt it, which could reduce the effectiveness of the first attack. Ransomware gangs can preserve their competitive advantage and increase their revenue by keeping their tools proprietary and exclusive.

Threat Profile:

References:

The following reports contain further technical details:

https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/play-ransomware-volume-shadow-copy

[/emaillocker]
crossmenu