HomeSecurityPlay ransomware follows the tactics of Hive and Nokoyawa

Play ransomware follows the tactics of Hive and Nokoyawa

Trend Micro in July investigated a series of ransomware attacks in the Latin American region targeting government agencies, initially attributed to a new player known as Play ransomware. The name of this ransomware comes from its behavior, as it appends the “.play” extension after encrypting files. Its ransom note contains the single word, “PLAY” and the ransomware group’s contact email address. Victims of this ransomware first appeared on the Bleeping Computer forums in June 2022. A month later, more details about the Play ransomware were published on the “No-logs No breach” website.

See also: QNAP fixes zero-day bug used by DeadBolt ransomware

Play ransomware follows the tactics of Hive and Nokoyawa

Further analysis of these ransomware infections, however, revealed that Play uses many tactics that follow the playbook of both Hive and Nokoyawa ransomware, including similarities in the filenames and file paths of the respective tools and payloads. Earlier this year, we found evidence suggesting that the attackers behind Nokayawa are related to those behind Hive, due to the many similarities between their attack chains.

See also: Los Angeles Unified School District: Hit by ransomware

In particular, one behavior that differentiates Play ransomware from Hive and Nokoyawa is its use of AdFind, a command-line search tool that can collect information from Active Directory (AD), as a means of discovery. Hive, on the other hand, has been observed using tools such as the TrojanSpy.DATASPY trojan to collect information on system .

play ransomware

Related malware campaigns

The many common tactics and tools suggest a high probability of collaboration between these ransomware families. This ransomware deserves further investigation and we plan to validate the associated URLs from Play ransomware infections for watermarking. This is to determine if they have indeed been associated with Hive infections in the past, as was previously done with Nokoyawa infections.

See also: Vice Society: FBI warns of ransomware attacks on school districts

Additionally, we found evidence that points to a possible connection between the Play ransomware and Quantum ransomware, which is an offshoot of the infamous Conti ransomware. The Cobalt Strike beacons used in the Play attacks carry the same watermark, 206546002, as those previously dropped by the Emotet and SVCReady botnets that have been observed in Quantum ransomware attacks. This suggests that the two ransomware groups share some of the same infrastructure.

During our research, we found a good chance of infection by Emotet. While there are currently no spam campaigns using the Emotet trojan, we have identified a few cases of Emotet being used to deploy Cobalt Strike beacons bearing the same watermark 206546002 found in beacons involved in Play ransomware attacks.

Infection routine

The malware creators behind the Play ransomware are known to use compromised legitimate accounts or exploit unpatched Fortinet SSL VPN vulnerabilities to gain access to an organization's network. Like most modern ransomware, Play uses LOLBins as part of its attacks.

play ransomware

Play ransomware also uses double extortion techniques against its victims. In its attacks, data extraction is performed before the ransomware is deployed: It archives a victim's files using WinRAR and then uploads the files to file-sharing websites. The ransomware executable is distributed via Group Policy Objects (GPO) and then executed using scheduled tasks, PsExec, or wmic.

More information can be found in Trend Micro's detailed research.

Information source: trendmicro.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS