Play Ransomware wird kommerziell - und wird jetzt als Service für Cyberkriminelle angeboten

Teilen:

The ransomware strain known as Play is now being offered to other threat actors “as a service,” new evidence unearthed by Adlumin has revealed.

“The unusual lack of even small variations between attacks suggests that they are being carried out by affiliates who have purchased the ransomware-as-a-service (RaaS) and are following step-by-step instructions from playbooks delivered with it,” the cybersecurity company said in a Bericht shared with The Hacker News.

The findings are based on various Play ransomware attacks tracked by Adlumin spanning different sectors that incorporated almost identical tactics and in the same sequence.

This includes the use of the public music folder (C:\…\public\music) to hide the malicious file, the same password to create high-privilege accounts, and both attacks, and the same commands.

Play, also called Balloonfly and PlayCrypt, first came to light in June 2022, leveraging security flaws in Microsoft Exchange Server – i.e., ProxyNotShell and OWASSRF – to infiltrate networks and drop remote administration tools like AnyDesk and ultimately deploy the ransomware.

Besides using custom data gathering tools like Grixba for double extortion, a notable aspect that set Play apart from other ransomware groups was the fact that the operators in charge of developing the malware also carried out the attacks.

The new development, therefore, marks a shift and completes its transformation into a RaaS operation, making it a lucrative option for cybercriminals.

“When RaaS operators advertise ransomware kits that come with everything a hacker will need, including documentation, forums, technical support, and ransom negotiation support, script kiddies will be tempted to try their luck and put their skills to use,” Adlumin said.

“And since there are probably more script kiddies than ‘real hackers’ today, businesses and authorities should take note and prepare for a growing wave of incidents.”

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
1:28 am, Juni 21, 2025
Wetter-Symbol 18°C
L: 17° | H: 19°
klarer Himmel
Luftfeuchtigkeit: 75 %
Druck: 1020 mb
Wind: 9 mph E
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 4%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:43 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
17° | 19°°C 0.25 mm 25% 9 mph 70 % 1020 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
17° | 26°°C 1 mm 100% 16 mph 88 % 1014 mb 0 mm/h
Mo. Juni 23 10:00 pm
Wetter-Symbol
15° | 24°°C 0.2 mm 20% 14 mph 77 % 1017 mb 0 mm/h
Di. Juni 24 10:00 pm
Wetter-Symbol
14° | 25°°C 0 mm 0% 12 mph 76 % 1017 mb 0 mm/h
Mi. Juni 25 10:00 pm
Wetter-Symbol
17° | 20°°C 1 mm 100% 11 mph 82 % 1011 mb 0 mm/h
Today 4:00 am
Wetter-Symbol
17° | 18°°C 0 mm 0% 5 mph 70 % 1020 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
20° | 20°°C 0 mm 0% 6 mph 57 % 1019 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
27° | 27°°C 0 mm 0% 8 mph 34 % 1018 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
30° | 30°°C 0 mm 0% 9 mph 25 % 1017 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
33° | 33°°C 0 mm 0% 8 mph 25 % 1016 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
30° | 30°°C 0 mm 0% 8 mph 28 % 1014 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
25° | 25°°C 0.25 mm 25% 6 mph 42 % 1014 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
20° | 20°°C 1 mm 100% 4 mph 74 % 1013 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€89,543.19
-1.44%
Ethereum(ETH)
€2,082.65
-5.04%
Fesseln(USDT)
€0.87
0.00%
XRP(XRP)
€1.84
-2.34%
Solana(SOL)
€121.29
-5.02%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.140834
-5.26%
Shiba Inu(SHIB)
€0.000010
-2.50%
Pepe(PEPE)
€0.000009
-4.29%
Peanut das Eichhörnchen(PNUT)
€0.218233
13.10%
Nach oben scrollen