CyberWire Daily - Play to win, pay to lose. [Research Saturday]

Episode Date: October 3, 2026

Today we are joined by Jean-Pierre Mouton, Senior Threat Intelligence Consultant at GuidePoint Security, discussing their work on "How Play Achieves Encryption." Play ransomware, also known as PlayCry...pt, continues to target organizations across multiple sectors using a consistent double-extortion playbook that combines data theft with widespread encryption. A recent investigation details how the group gained access through a SonicWall VPN, moved laterally using tools such as Mimikatz and PsExec, exfiltrated sensitive data, and used the victim’s own SentinelOne uninstallation utility to disable endpoint protection. The findings highlight several behavioral indicators defenders can monitor, including tool staging through SYSVOL and SystemBC for command and control, event log clearing, and suspicious WinSCP activity. The research and executive brief can be found here: ⁠⁠⁠⁠How Play Achieves Encryption Learn more about your ad choices. Visit megaphone.fm/adchoices

Transcript
Discussion (0)
Starting point is 00:00:00 You're listening to the Cyberwire Network, powered by N2K. When initial access vulnerabilities are cheap and automated, attackers can hit everything all the time. But at Black Hat, OpenAI's Clint Gibbler and Spectorops's Robbie Winchester reminded me that we don't have to just fight AI with AI at machine speed. By taking a preventative mindset, defenders can mitigate attack pathways so there's far less occurring. at machine speed in the first place. Listen to our full black hat conversation at explore.thecyberwire.com slash specterops.
Starting point is 00:00:49 DLP sucks. Every CISO knows it. 20 years of rules and reg X built for another era. Jazz is the DLP that deeply understands your business. Melody, Jazz's agentic investigator, weighs every data movement against the data, systems, people in process, then provides analysts with the few incidents fully investigated. In 30 days, 2 million signals in, about 80 investigated incidents out.
Starting point is 00:01:19 No rules written. Jazz won the 2026 CrowdStrike AWS and NVIDIA startup accelerator from a nearly thousand applicants. See Melody inaction at jazz.security slash N2K. Hello, everyone, and welcome. to the Cyberwires Research Saturday. I'm Dave Bittner, and this is our weekly conversation with researchers and analysts tracking down the threats and vulnerabilities, solving some of the hard problems and protecting ourselves in a rapidly evolving cyberspace. Thanks for joining us.
Starting point is 00:02:06 One of our partner insurance carriers came to us with a client who had been encrypted by play, and we took on the case from both a forensics and a ransomware. negotiation inside. That's Jean-Pierre Mouton, senior threat intelligence consultant at GuidePoint Security. The research we're discussing today is titled How Play Achieves Encryption. Let's start with Play itself. What distinguishes this ransomware operation from some of the other ransomware as-a-service models?
Starting point is 00:02:52 Absolutely. So one of the major things that differentiates them from the ransomware as-a-service models is that they operate nominally or what they say themselves specifically on their dark web leak site is a closed model, meaning they actually have a singular team of operators as well as hands-on keyboard hackers or however you would like to term them that work together from the instance of breaching a victim network all the way through negotiations and receiving payment. Whereas the ransomware as a service operators, you were what used to be Ransom Hub or Key Lin, Dragon Force is a big one these days. They operate a core group of operators
Starting point is 00:03:37 who maintain the encryption software and the data leak site itself, but they contract out the initial operations, if you will, against victim organizations to what they call affiliates or members who are not part of the core group, but do do operations on their behalf and they receive a cut of the final payment. So your research here follows an incident from earlier this year that pretty well-followed plays established playbook pretty closely. Can you walk us through that? What typically happens when you're dealing with play specifically?
Starting point is 00:04:17 So one of the things that we have noticed in all of our engagements that include play as the threat actor is they will typically start with an edge-divor. that they'll compromise to gain access to the environment. Then they will dump credentials or use other avenues of achieving or retrieving credentials on the local machine in order to pivot to either more escalated privileges or other devices on the network. And then they'll move from there to full network compromise and push encryption to everything after they have
Starting point is 00:04:56 exfiltrated data. In this case, in particular, they actually went through the sonic wall, BPN process that this client had. And from there, used the MimiCats, which is well known at this point
Starting point is 00:05:11 in the industry, I believe, tool in order to dump those credentials that were on the local machine. And then they pivoted to an active directory where they staged everything, on the system volume that shares across the entire network. By everything, I mean they staged their tooling,
Starting point is 00:05:31 they staged the data for Axville, and then use that to push encryption across the entire network. Yeah, I thought one of the notable things in your research was that the earliest attacker attributed logon that you all tracked was about two and a half months before encryption. What does that tell us about the pace and the patience of these operators? Absolutely. So Play is one of those operators that we see with a longer dwell time, meaning they stay on environment longer than most operators. And this is because they're very methodical in their approach to one breaching the network, but also staging and exfiltrating the data that they find interesting, if you will. So what this tells us is unlike the Dragon Forces or the RAS operators that we see out there. they get in, do deep reconnaissance to figure out where they need to go next,
Starting point is 00:06:31 identify what credentials they need to retrieve in order to flip their access to higher system or admin access, and then they will do more reconnaissance, figure out where the data is, where the sensitive data is, and then pull that together in a development process for, For instance, in this case, they had a PowerShell script that did most of the data pooling into the SISFOL and Perf Logs directory. And then once all of that is done, which takes a while, as you can imagine, to do it without getting caught on a regular basis, then they push encryption out. So it's more of their methodical approach compared to other operators that has led to them getting longer dwell times. Yeah, can we dig into that?
Starting point is 00:07:24 I mean, what are some of the methods that they're using here to keep themselves from getting caught? One of the main things that they're using to keep themselves from getting caught, which we do state specifically in the research, is that they're using directories and locations on the network and on these endpoints where the monitoring is not as robust as you would expect on like your C drive or. just your documents or your desktop or any of those where the actual virus scanners or endpoint detection and response systems, the EDRs are looking for that malicious scripts or malware to be. So they're using those paths, which are low scrutiny, and then they're doing most of their work as far as maintaining access in those directories. And because it's low scrutiny, more times than not, they're actually not being scanned for the specific indicators that you would see for persistence on other operators.
Starting point is 00:08:35 One of the evasion techniques here really caught my eye. It was an EDR evasion technique. You point out that they used the victim's own Sentinel One removal utility. Walk us through how that works. Yeah, so every one of the EDRs and virus scanning tools that are out there, they want you to be able to uninstall their tool whenever you're moving to something else, or just in general administrative procedures, for instance, when you're offline in a device that's end of life or something like that.
Starting point is 00:09:10 So what they did was once they had gotten administrative access on those devices or across the network through the active directory, they used that standard application in order to remove Sentinel One itself. And it was completely staged on the device by the developer. It comes with every package whenever you install Sentinel One and allowed them to just run the application for uninstalling and everything was gone as you would expect. Now, is that a case where since you've given Sentinel One permission to install its app,
Starting point is 00:09:53 that it's assumed that it also has permission to uninstall? Yes, absolutely. Okay. Yeah. Interesting. Interesting. They also cleared out the Windows security logs, you know, from a defender's perspective, what does an event like that tell you?
Starting point is 00:10:11 It tells me that they do not want to get caught. So whenever we're engaging in these digital forensics investigations, one of the main things that we're doing besides looking for what data has been accessed by the TA is also looking for indicators of how they accessed, what they accessed, when they accessed, dwell time, all of those sort of holistic data points so that we can track the TA, what their tactics, techniques, procedures are on keyboard themselves. So this is one of those groups that actually goes out of their way in order to remove that capability for defenders because they do not want their tactics out there or anyone to be able to stop them. And actually it goes against their ability to maintain anonymity and be on network and actually come across with those actions on keyboard within the breach in order for defenders to, you know, see those processes, those. tactics and put a stop to them through alerting or yarr rules, etc. We'll be right back. In Toronto, every arrival is a statement and nothing says it better than this. Cadillac Optic was the number one selling luxury EV in Canada for 2025.
Starting point is 00:11:36 Find your rhythm across a seamless 33-inch display and an immersive 19 speaker AKG surround audio system. This city demands agility and Optic delivers with precision to make every drive extraordinary. Let's take the Cadillac. Find out more at Cadillac Canada.ca. Luxury sales claim based on S&P Global Mobility, Canadian New Vehicle Total Registrations for calendar year 2025 for the Cadillac definition of luxury. Every time your team deploys a new cloud workload or AI agent,
Starting point is 00:12:04 another identity gets permanent access to your critical systems. Legacy tools were built to manage human employees, leaving modern machine and AI access largely unmanaged. That's where IDRUra, by Palo Alto Networks comes in. Human, machine, AI, one identity platform for all. IDIRA replaces permanent permissions with dynamic access, so you can lock down every identity without slowing down your business. Secure every identity with IDIRA by Palo Alto Networks. Visit Palo Alto Networks slash IDERA. Again, that's palo Alto Networks.com slash IDI.
Starting point is 00:12:48 My name is Siaiaa, and I live in the most beautiful place on earth. Seven months ago, I blew up my life, and a lot has shifted since then. Everyone is moving forward. I'm still working on that. And that's me. Welcome to Ice Cove. Where are the penguins? That's Antarctica.
Starting point is 00:13:16 We're the other one. North of North. Stream all episodes, available on CBCJM. And now a word from our sponsor, SpectorOps. Today, AI is rapidly adding non-human and agentic identities to modern enterprise environments, creating new trust relationships and attack paths. Bloodhound Enterprise helps defenders map attack paths across AWS and hybrid environments
Starting point is 00:13:50 as one connected graph, identify the choke points that matter most, and bring trusted attack path intelligence into approved AI workflows with Bloodhound Hunter. See how SpectorOps helps teams secure the AI-driven identity era at Spectorops.io. Well, let's dig into the encryptor itself. How was play distributing and executing the ransomware across the environment? So one of the things that we actually see from other groups is they will use group policy objects, which is
Starting point is 00:14:36 administrative controls on Windows specifically to create a rule that pushes their encryptor out to the entire network that the GPO has access to. Play took this a separate way
Starting point is 00:14:51 in that they decided to go for the SISFOL or the system volume on the active directory and stage the encryptor there. What that means is active directory controls all of the devices on the network that is keyed into the active directory system itself.
Starting point is 00:15:10 And the SISFOL on the active directory is actually a shared volume that is pushed to every single device that is locked into that active directory. So it appears on every single device on the network controlled by the active directory. I'm saying active directory a lot, but it's very important.
Starting point is 00:15:30 So whenever they put their encryptor on that SISFOL shared volume, it automatically pushed everything out to the network itself that's connected to the active directory without the need to modify any GPO policies or go through any of the other traditional admin steps that threat actors use in order to do network-wide encryption. So it's a very, I don't want to say novel,
Starting point is 00:16:00 but unique way that they're encrypting the entire network without doing something that defenders are normally looking for because most defensive applications and procedures these days are looking for that GPO policy edit that will immediately alert to this is bad and it shouldn't be pushed out and it was created specifically for this reason, which is just another one of those detection mechanisms that we look for. specifically whenever we're doing our forensics investigations. There was an interesting forensic artifact that you highlighted. It was actually a failure. There was an encryptor crash dump.
Starting point is 00:16:43 What was the value of that to you all as investigators? Absolutely. So this in particular gives us a unique look into what the encryptor is doing and how they're staging it. Because the encryptor failed, there was a log produced. on the end point that showed what the encryptor was trying to do, where it was going next, and what it was connecting to. So that gave us a little bit of a look into where the command and control was,
Starting point is 00:17:12 what living off the land evasion techniques they would potentially be using, as well as what tools they had staged in order to support that entire mechanism itself. So we got a little bit more of a granular view into what they were attempting to accomplish and how they were attempting to do it compared to if that crash hadn't have happened because they were so meticulous in deleting all of the other logs. Now, there was a point where Windows Defender detected some ransomware activity on a domain controller. What did that tell us? Describe that for me, please. So whenever it comes to that action in particular, what it tells us is that their encryptor,
Starting point is 00:18:00 is actually recognized by standard defender logic, meaning it was recognized and it was blocked. However, that only occurred on one machine, and that tells us that there was an error outside of that failure that we had just discussed that allowed this machine to not be effectively shut down when it comes to a defender. And it's just another data point as to how you can, block it if everything operates correctly and they're not able to completely remove all of the
Starting point is 00:18:37 security protocols that are in place. So in this case, Windows Defender flagging it was kind of an anomaly? Yes, absolutely, especially with play. Compared to the activity, yeah. Yes, absolutely. No, no, no, I was essentially going to say the same thing you were going to. Compared to what normally happens or what happened on the rest of the environment, it was absolutely an anomaly. And I don't think they expected it or were even aware that it happened. One of the things that you point out in the research is that play's consistency may create opportunities for behavioral detection. What are the strongest behaviors that defenders could hunt for before that encryption stage?
Starting point is 00:19:25 Yeah. So previously, I had mentioned that they were using SISFOL as their way to push the encryptor out across the network. Specifically on the SISFOL, they were using a directory called Perflogs. Now, this Perflogs is present on the active directory device under the SISFOL, but it's also present on every endpoint as well in your C directory or your C drive itself. we identified, I want to say, correct me if I'm wrong here, or don't quote me if I'm wrong here, but somewhere around 11 artifacts within the engagement itself, all of which were staged in that Perf logs directory. And it's not usual for threat actors to use the same directory over and over again for staging their tools and exfiltration of data in the, that sort of directory. Mostly we'll see it happening in like the temp files under the user data
Starting point is 00:20:26 or app data roaming temp, those sorts of directories. But consistently over three to four cases that we've worked since mid-20205, all of the data and all of the tools have been staged specifically in that Perflogs directory. So that's a great indicator as far as how or where they're staging the data prior to exfiltration. Well, more broadly speaking, what are your recommendations then? Based on all this information you've gathered, how should people best protect themselves against play? That is a very good question.
Starting point is 00:21:07 We outline it kind of in the blog itself, but one of the things that we would recommend is tightening security access controls across your entire environment, environment and that includes escalating EDR uninstallation capabilities to the highest level. Additionally, monitoring for any
Starting point is 00:21:29 sort of proxy C2 behavior. Play likes to use System B.C. As their backdoor, if you will, persistence mechanism on environment. And monitoring for that specifically is effective
Starting point is 00:21:44 because it uses the SOX-5 proxy. and most of the C2 that we're seeing nowadays don't use that as much anymore because it is so widely known as an indicator for abuse. So that's one method as well as just focusing on behavioral detections in general to catch repeatable adversary playbooks. And that, like I said, would be most of your remote access Trojans, any cobalt strike tagged connections that are happening.
Starting point is 00:22:17 which is widely distributed at this point and then additionally just looking for any changes in data manipulation as far as moving them staging them in certain directories on on the network itself those are all great baseline indicators that you can start with and then move on to more robust things such as implementing your rules I think CISA has quite a robust amount of YAR rules established specifically for play that they published in their Stop Ransomware Play blog itself. So that would be a great resource to look for defensive recommendations. And who do we suppose we're dealing with here?
Starting point is 00:23:04 Do we have any confidence in attribution? I would be remiss if I made any sort of... conjecture regarding that. We can obviously make guesses, but there's no way to really tell based on how they're connecting. Using the Tor network to connect out to victim environments really obfuscates
Starting point is 00:23:30 the connections themselves with the IPs used and everything. So we can guess, but there's no way of knowing for sure. I think CISA wants to say that they are Russian in nature, but we at Guidepoint cannot be sure of what they are specifically. Our thanks to Jean-Pierre Mouton from GuidePoint for joining us. The research is titled How Play Achieves Encryption.
Starting point is 00:24:07 We'll have a link in the show notes. And that's Research Saturday, brought to you by N2K Cyberwire. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world. of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey and the show notes or send an email to Cyberwire at n2k.com. This episode was produced by Liz Stokes. We're mixed by Elliot Peltzman and Trey Hester. Our executive producer is Jennifer Iben. Peter Kilpe is our publisher, and I'm Dave Bittner.
Starting point is 00:24:44 Thanks for listening. We'll see you back here next time. I was an Avenger, but I'm not a hero anymore. It's like I'm losing my... On October 14th, the Vision returns for the final chapter of the groundbreaking trilogy. That family wasn't real. You sure about that? I had a father called Vision. How is this possible?
Starting point is 00:25:16 Don't miss the two-episode premiere of Marvel Television's Vision Quest. Nothing bonds a family together quite like Mortal Jeopardy. Streaming October 14th. Only on Disney Plus. Hey, everybody, Dave here. I want to let you know about a special gathering hosted by Zimperium at the Spy Museum in Washington, D.C. This invitation-only event will bring together federal cybersecurity and technology leaders to discuss some of the most pressing challenges facing government today, including mobile security, mission resilience, and the evolving threat landscape.
Starting point is 00:25:53 I'm always grateful for opportunities to spend time with smart people doing important work, and I'm excited to be part of these conversations. I hope to see some familiar faces there. If you're interested in attending, you can request an invitation. You'll find more information in our show notes. Our thanks to Zimperium for sponsoring this event. We'll see you there. Where some see heroes and others see egos.
Starting point is 00:26:23 Bloomberg sees the era of billionaire athletes. A fad to some, the future of money to others. We see crypto's trillion-dollar swings. the end of jobs or the end of human struggle. We see the endless funds fueling the AI hype. While others follow the noise, we follow the money. Learn more at Bloomberg.com.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.