CyberWire Daily - Play to win, pay to lose. [Research Saturday]
Episode Date: October 3, 2026Today we are joined by Jean-Pierre Mouton, Senior Threat Intelligence Consultant at GuidePoint Security, discussing their work on "How Play Achieves Encryption." Play ransomware, also known as PlayCry...pt, continues to target organizations across multiple sectors using a consistent double-extortion playbook that combines data theft with widespread encryption. A recent investigation details how the group gained access through a SonicWall VPN, moved laterally using tools such as Mimikatz and PsExec, exfiltrated sensitive data, and used the victim’s own SentinelOne uninstallation utility to disable endpoint protection. The findings highlight several behavioral indicators defenders can monitor, including tool staging through SYSVOL and SystemBC for command and control, event log clearing, and suspicious WinSCP activity. The research and executive brief can be found here: How Play Achieves Encryption Learn more about your ad choices. Visit megaphone.fm/adchoices
Transcript
Discussion (0)
You're listening to the Cyberwire Network, powered by N2K.
When initial access vulnerabilities are cheap and automated, attackers can hit everything all the time.
But at Black Hat, OpenAI's Clint Gibbler and Spectorops's Robbie Winchester reminded me that we don't have to just fight AI with AI at machine speed.
By taking a preventative mindset, defenders can mitigate attack pathways so there's far less occurring.
at machine speed in the first place.
Listen to our full black hat conversation
at explore.thecyberwire.com
slash specterops.
DLP sucks.
Every CISO knows it.
20 years of rules and reg X built for another era.
Jazz is the DLP that deeply understands your business.
Melody, Jazz's agentic investigator,
weighs every data movement against the data,
systems, people in process, then provides analysts with the few incidents fully investigated.
In 30 days, 2 million signals in, about 80 investigated incidents out.
No rules written.
Jazz won the 2026 CrowdStrike AWS and NVIDIA startup accelerator from a nearly
thousand applicants.
See Melody inaction at jazz.security slash N2K.
Hello, everyone, and welcome.
to the Cyberwires Research Saturday. I'm Dave Bittner, and this is our weekly conversation with
researchers and analysts tracking down the threats and vulnerabilities, solving some of the hard
problems and protecting ourselves in a rapidly evolving cyberspace. Thanks for joining us.
One of our partner insurance carriers came to us with a client who had been encrypted by
play, and we took on the case from both a forensics and a ransomware.
negotiation inside.
That's Jean-Pierre Mouton, senior threat intelligence consultant at GuidePoint Security.
The research we're discussing today is titled How Play Achieves Encryption.
Let's start with Play itself.
What distinguishes this ransomware operation from some of the other ransomware as-a-service
models?
Absolutely.
So one of the major things that differentiates them from the ransomware as-a-service models is
that they operate nominally or what they say themselves specifically on their dark web
leak site is a closed model, meaning they actually have a singular team of operators as well as
hands-on keyboard hackers or however you would like to term them that work together from the
instance of breaching a victim network all the way through negotiations and receiving
payment. Whereas the ransomware as a service operators, you were what used to be
Ransom Hub or Key Lin, Dragon Force is a big one these days. They operate a core group of operators
who maintain the encryption software and the data leak site itself, but they contract out the
initial operations, if you will, against victim organizations to what they call affiliates
or members who are not part of the core group, but do do operations on their behalf and they
receive a cut of the final payment.
So your research here follows an incident from earlier this year that pretty well-followed
plays established playbook pretty closely.
Can you walk us through that?
What typically happens when you're dealing with play specifically?
So one of the things that we have noticed in all of our engagements that include play as
the threat actor is they will typically start with an edge-divor.
that they'll compromise to gain access to the environment.
Then they will dump credentials or use other avenues of achieving or retrieving
credentials on the local machine in order to pivot to either more escalated privileges
or other devices on the network.
And then they'll move from there to full network compromise and push encryption to everything
after they have
exfiltrated data.
In this case, in particular,
they actually
went through the sonic wall,
BPN process that this client had.
And from there,
used the MimiCats,
which is well known at this point
in the industry, I believe,
tool in order to dump those credentials
that were on the local machine.
And then they pivoted to
an active directory
where they staged everything,
on the system volume that shares across the entire network.
By everything, I mean they staged their tooling,
they staged the data for Axville,
and then use that to push encryption across the entire network.
Yeah, I thought one of the notable things in your research
was that the earliest attacker attributed logon
that you all tracked was about two and a half months before encryption.
What does that tell us about the pace and the patience of these operators?
Absolutely. So Play is one of those operators that we see with a longer dwell time, meaning they stay on environment longer than most operators. And this is because they're very methodical in their approach to one breaching the network, but also staging and exfiltrating the data that they find interesting, if you will. So what this tells us is unlike the Dragon Forces or the RAS operators that we see out there.
they get in, do deep reconnaissance to figure out where they need to go next,
identify what credentials they need to retrieve in order to flip their access to
higher system or admin access, and then they will do more reconnaissance,
figure out where the data is, where the sensitive data is,
and then pull that together in a development process for,
For instance, in this case, they had a PowerShell script that did most of the data pooling into the SISFOL and Perf Logs directory.
And then once all of that is done, which takes a while, as you can imagine, to do it without getting caught on a regular basis, then they push encryption out.
So it's more of their methodical approach compared to other operators that has led to them getting longer dwell times.
Yeah, can we dig into that?
I mean, what are some of the methods that they're using here to keep themselves from getting caught?
One of the main things that they're using to keep themselves from getting caught, which we do state specifically in the research, is that they're using directories and locations on the network and on these endpoints where the monitoring is not as robust as you would expect on like your C drive or.
just your documents or your desktop or any of those where the actual virus scanners or
endpoint detection and response systems, the EDRs are looking for that malicious scripts or malware
to be. So they're using those paths, which are low scrutiny, and then they're doing most of their
work as far as maintaining access in those directories.
And because it's low scrutiny, more times than not, they're actually not being scanned
for the specific indicators that you would see for persistence on other operators.
One of the evasion techniques here really caught my eye.
It was an EDR evasion technique.
You point out that they used the victim's own Sentinel One removal utility.
Walk us through how that works.
Yeah, so every one of the EDRs and virus scanning tools that are out there,
they want you to be able to uninstall their tool whenever you're moving to something else,
or just in general administrative procedures, for instance,
when you're offline in a device that's end of life or something like that.
So what they did was once they had gotten administrative access on those devices
or across the network through the active directory,
they used that standard application in order to remove Sentinel One itself.
And it was completely staged on the device by the developer.
It comes with every package whenever you install Sentinel One
and allowed them to just run the application for uninstalling
and everything was gone as you would expect.
Now, is that a case where since you've given Sentinel One permission to install its app,
that it's assumed that it also has permission to uninstall?
Yes, absolutely.
Okay.
Yeah.
Interesting.
Interesting.
They also cleared out the Windows security logs, you know, from a defender's perspective,
what does an event like that tell you?
It tells me that they do not want to get caught.
So whenever we're engaging in these digital forensics investigations, one of the main things that we're doing besides looking for what data has been accessed by the TA is also looking for indicators of how they accessed, what they accessed, when they accessed, dwell time, all of those sort of holistic data points so that we can track the TA, what their tactics, techniques, procedures are on keyboard themselves.
So this is one of those groups that actually goes out of their way in order to remove that capability for defenders because they do not want their tactics out there or anyone to be able to stop them.
And actually it goes against their ability to maintain anonymity and be on network and actually come across with those actions on keyboard within the breach in order for defenders to, you know, see those processes, those.
tactics and put a stop to them through alerting or yarr rules, etc.
We'll be right back.
In Toronto, every arrival is a statement and nothing says it better than this.
Cadillac Optic was the number one selling luxury EV in Canada for 2025.
Find your rhythm across a seamless 33-inch display and an immersive 19 speaker AKG surround audio system.
This city demands agility and Optic delivers with precision to make every drive extraordinary.
Let's take the Cadillac.
Find out more at Cadillac Canada.ca.
Luxury sales claim based on S&P Global Mobility,
Canadian New Vehicle Total Registrations for calendar year 2025
for the Cadillac definition of luxury.
Every time your team deploys a new cloud workload or AI agent,
another identity gets permanent access to your critical systems.
Legacy tools were built to manage human employees,
leaving modern machine and AI access largely unmanaged.
That's where IDRUra,
by Palo Alto Networks comes in. Human, machine, AI, one identity platform for all.
IDIRA replaces permanent permissions with dynamic access, so you can lock down every identity
without slowing down your business. Secure every identity with IDIRA by Palo Alto Networks.
Visit Palo Alto Networks slash IDERA. Again, that's palo Alto Networks.com slash IDI.
My name is Siaiaa, and I live in the most beautiful place on earth.
Seven months ago, I blew up my life, and a lot has shifted since then.
Everyone is moving forward.
I'm still working on that.
And that's me.
Welcome to Ice Cove.
Where are the penguins?
That's Antarctica.
We're the other one.
North of North.
Stream all episodes, available on CBCJM.
And now a word from our sponsor, SpectorOps.
Today, AI is rapidly adding non-human and agentic identities
to modern enterprise environments,
creating new trust relationships and attack paths.
Bloodhound Enterprise helps defenders map attack paths across AWS and hybrid environments
as one connected graph,
identify the choke points that matter most,
and bring trusted attack path intelligence into approved AI workflows with Bloodhound Hunter.
See how SpectorOps helps teams secure the AI-driven identity era at Spectorops.io.
Well, let's dig into the encryptor itself.
How was play distributing and executing the ransomware across the environment?
So one of the things that we actually see from other groups is they will use
group policy objects, which is
administrative controls
on Windows specifically to
create a rule that pushes their
encryptor out to the entire
network that the GPO
has access
to. Play took this
a separate way
in that they decided
to go for the SISFOL
or the system volume on the active
directory and stage
the encryptor there. What that
means is active directory
controls all of the devices on the network
that is keyed into the active directory system itself.
And the SISFOL on the active directory
is actually a shared volume
that is pushed to every single device
that is locked into that active directory.
So it appears on every single device on the network
controlled by the active directory.
I'm saying active directory a lot,
but it's very important.
So whenever they put their encryptor
on that SISFOL shared volume,
it automatically pushed everything out to the network itself
that's connected to the active directory
without the need to modify any GPO policies
or go through any of the other traditional admin steps
that threat actors use in order to do network-wide encryption.
So it's a very, I don't want to say novel,
but unique way that they're encrypting the entire network without doing something that defenders are
normally looking for because most defensive applications and procedures these days are looking
for that GPO policy edit that will immediately alert to this is bad and it shouldn't be pushed out
and it was created specifically for this reason, which is just another one of those detection mechanisms that we look for.
specifically whenever we're doing our forensics investigations.
There was an interesting forensic artifact that you highlighted.
It was actually a failure.
There was an encryptor crash dump.
What was the value of that to you all as investigators?
Absolutely.
So this in particular gives us a unique look into what the encryptor is doing and how they're
staging it.
Because the encryptor failed, there was a log produced.
on the end point that showed what the encryptor was trying to do,
where it was going next, and what it was connecting to.
So that gave us a little bit of a look into where the command and control was,
what living off the land evasion techniques they would potentially be using,
as well as what tools they had staged in order to support that entire mechanism itself.
So we got a little bit more of a granular view into what they were attempting to
accomplish and how they were attempting to do it compared to if that crash hadn't have happened
because they were so meticulous in deleting all of the other logs.
Now, there was a point where Windows Defender detected some ransomware activity on a domain
controller. What did that tell us? Describe that for me, please.
So whenever it comes to that action in particular, what it tells us is that their encryptor,
is actually recognized by standard defender logic,
meaning it was recognized and it was blocked.
However, that only occurred on one machine,
and that tells us that there was an error outside of that failure
that we had just discussed that allowed this machine to not be effectively shut down
when it comes to a defender.
And it's just another data point as to how you can,
block it if everything operates correctly and they're not able to completely remove all of the
security protocols that are in place. So in this case, Windows Defender flagging it was kind of an
anomaly? Yes, absolutely, especially with play. Compared to the activity, yeah. Yes, absolutely.
No, no, no, I was essentially going to say the same thing you were going to. Compared to what normally
happens or what happened on the rest of the environment, it was absolutely an anomaly.
And I don't think they expected it or were even aware that it happened.
One of the things that you point out in the research is that play's consistency may create
opportunities for behavioral detection. What are the strongest behaviors that defenders could
hunt for before that encryption stage?
Yeah.
So previously, I had mentioned that they were using SISFOL as their way to push the encryptor out across the network.
Specifically on the SISFOL, they were using a directory called Perflogs.
Now, this Perflogs is present on the active directory device under the SISFOL, but it's also present on every endpoint as well in your C directory or your C drive itself.
we identified, I want to say, correct me if I'm wrong here, or don't quote me if I'm wrong here,
but somewhere around 11 artifacts within the engagement itself, all of which were staged in that Perf logs directory.
And it's not usual for threat actors to use the same directory over and over again for staging their tools and exfiltration of data in the,
that sort of directory. Mostly we'll see it happening in like the temp files under the user data
or app data roaming temp, those sorts of directories. But consistently over three to four cases that
we've worked since mid-20205, all of the data and all of the tools have been staged specifically
in that Perflogs directory. So that's a great indicator as far as how or where they're staging the data
prior to exfiltration.
Well, more broadly speaking, what are your recommendations then?
Based on all this information you've gathered,
how should people best protect themselves against play?
That is a very good question.
We outline it kind of in the blog itself,
but one of the things that we would recommend is
tightening security access controls across your entire environment,
environment and that includes
escalating
EDR uninstallation
capabilities to the highest level.
Additionally, monitoring for any
sort of proxy C2 behavior.
Play likes to use System B.C.
As their
backdoor, if you will,
persistence mechanism on
environment. And
monitoring for that
specifically is effective
because it uses the SOX-5 proxy.
and most of the C2 that we're seeing nowadays
don't use that as much anymore
because it is so widely known as an indicator for abuse.
So that's one method as well as just focusing on behavioral detections
in general to catch repeatable adversary playbooks.
And that, like I said, would be most of your remote access Trojans,
any cobalt strike tagged connections that are happening.
which is widely distributed at this point and then additionally just looking for any
changes in data manipulation as far as moving them staging them in certain
directories on on the network itself those are all great baseline indicators that you
can start with and then move on to more robust things such as implementing your rules
I think CISA has quite a robust amount of YAR rules established specifically for play
that they published in their Stop Ransomware Play blog itself.
So that would be a great resource to look for defensive recommendations.
And who do we suppose we're dealing with here?
Do we have any confidence in attribution?
I would be remiss if I made any sort of...
conjecture regarding that.
We can obviously make guesses,
but there's no way to really tell
based on how they're connecting.
Using the Tor network to connect out
to victim environments really obfuscates
the connections themselves
with the IPs used and everything.
So we can guess,
but there's no way of knowing for sure.
I think CISA wants to say
that they are Russian in nature, but we at Guidepoint cannot be sure of what they are specifically.
Our thanks to Jean-Pierre Mouton from GuidePoint for joining us.
The research is titled How Play Achieves Encryption.
We'll have a link in the show notes.
And that's Research Saturday, brought to you by N2K Cyberwire.
We'd love to know what you think of this podcast.
Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world.
of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app.
Please also fill out the survey and the show notes or send an email to Cyberwire at n2k.com.
This episode was produced by Liz Stokes. We're mixed by Elliot Peltzman and Trey Hester.
Our executive producer is Jennifer Iben. Peter Kilpe is our publisher, and I'm Dave Bittner.
Thanks for listening. We'll see you back here next time.
I was an Avenger, but I'm not a hero anymore.
It's like I'm losing my...
On October 14th, the Vision returns for the final chapter of the groundbreaking trilogy.
That family wasn't real.
You sure about that?
I had a father called Vision.
How is this possible?
Don't miss the two-episode premiere of Marvel Television's Vision Quest.
Nothing bonds a family together quite like Mortal Jeopardy.
Streaming October 14th. Only on Disney Plus.
Hey, everybody, Dave here.
I want to let you know about a special gathering hosted by Zimperium at the Spy Museum in Washington, D.C.
This invitation-only event will bring together federal cybersecurity and technology leaders
to discuss some of the most pressing challenges facing government today,
including mobile security, mission resilience, and the evolving threat landscape.
I'm always grateful for opportunities to spend time with smart people doing important work,
and I'm excited to be part of these conversations.
I hope to see some familiar faces there.
If you're interested in attending, you can request an invitation.
You'll find more information in our show notes.
Our thanks to Zimperium for sponsoring this event.
We'll see you there.
Where some see heroes and others see egos.
Bloomberg sees the era of billionaire athletes.
A fad to some, the future of money to others.
We see crypto's trillion-dollar swings.
the end of jobs or the end of human struggle.
We see the endless funds fueling the AI hype.
While others follow the noise, we follow the money.
Learn more at Bloomberg.com.
