The Play ransomware gang exploited a serious security flaw in the Windows Common Log File System, carrying out zero-day attacks to gain SYSTEM-level privileges and install malware on compromised systems.
See also: LockBit ransomware group suffered a serious data leak

The vulnerability, codenamed CVE-2025-29824, was identified by Microsoft as being exploited in a limited number of attacks and was patched in Patch Tuesday . Microsoft linked these attacks to the RansomEXX ransomware, saying that the attackers installed the PipeMagic backdoor malware, which was used to execute CVE-2025-29824, install ransomware payloads, and display ransom notes after encrypting files.
Since then, Symantec's Threat Hunter team found evidence linking this activity to the ransomware-as-a-service platform Play, reporting that the attackers used the CVE-2025-29824 zero-day to escalate privileges after first breaching the network of an organization in the United States.
The custom network scanning and information theft tool Grixba was first detected two years ago, and Play ransomware operators commonly use it to record users and computers on compromised networks.
See also: New EDR bypass “Bring Your Own Installer” used in ransomware attacks
The Play criminal group emerged in June 2022 and is also known for its double extortion attacks, in which its partners force victims to pay a ransom to prevent stolen data online.

In December 2023, the FBI issued a joint alert along with CISA and the Australian Cyber Security Centre (ACSC), warning that by October 2023, the Play gang had breached the networks of approximately 300 organisations worldwide.
Play's most well-known victims include cloud computing company Rackspace , car dealership giant Arnold Clark , the city of Oakland in California, Dallas County , the Belgian city of Antwerp , and more recently, American semiconductor supplier Microchip Technology and doughnut chain Krispy Kreme .
See also: Ransomware attacks decrease in April (+ most significant incidents)
Relatedly, ransomware gangs like Play are now adopting sophisticated attack tactics similar to those of state-sponsored groups. Specifically, they are using tools like Grixba for network reconnaissance, undetectable backdoors to persist in the system, and double-blackmail techniques to maximize pressure on victims. The fact that they have targeted organizations like municipalities, cloud computing companies, and semiconductor suppliers suggests that they are focusing on critical infrastructure with a high impact in the event of an outage.
Source: bleepingcomputer
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
