Skip to content
TrackPodcasts
newsOct 3, 202623:11

Play to win, pay to lose. [Research Saturday]

CyberWire Daily

Get every episode summarized

Each time CyberWire Daily publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

About this episode

“When initial access vulnerabilities are cheap and automated, attackers can hit everything all the time. But at Black Hat, open AI's Clint Gibler and Spectorops' Robby Winchester reminded me that we don't have to just fight AI with AI at machine speed.”From the transcript

Today we are joined by Jean-Pierre Mouton, Senior Threat Intelligence Consultant at GuidePoint Security, discussing their work on "How Play Achieves Encryption." Play ransomware, also known as PlayCrypt, continues to target organizations across multiple sectors using a consistent double-extortion playbook that combines data theft with widespread encryption. A recent investigation details how the group gained access through a SonicWall VPN, moved laterally using tools such as Mimikatz and PsExec, exfiltrated sensitive data, and used the victim’s own SentinelOne uninstallation utility to disable endpoint protection. The findings highlight several behavioral indicators defenders can monitor, including tool staging through SYSVOL and SystemBC for command and control, event log clearing, and suspicious WinSCP activity. The research and executive brief can be found here: ⁠⁠⁠⁠How Play Achieves Encryption Learn more about your ad choices. Visit megaphone.fm/adchoices

Hosts & guests

Transcript ready

163 searchable segments. Every word is indexed and playable.

Play to win, pay to lose. [Research Saturday]

CyberWire Daily

0:00
23:11

Full transcript

CyberWire Daily — Play to win, pay to lose. [Research Saturday]. Machine-transcribed; use the interactive transcript above to jump the player to any line.

You're listening to the CyberWire network, powered by N2K. When initial access vulnerabilities are cheap and automated, attackers can hit everything all the time. But at Black Hat, open AI's Clint Gibler and Spectorops' Robby Winchester reminded me that we don't have to just fight AI with AI at machine speed. By taking a preventative mindset, defenders can mitigate attack pathways so there's far less occurring at machine speed in the first place. Listen to our full Black Hat conversation at explore.thecyberwire.com slash Spectorops. DLP sucks. Every syso knows it. 20 years of rules and reg X built for another era. Jazz is the DLP that deeply understands your business.

Melody, Jazz's agentic investigator, weighs every data movement against the data, systems, people, and process, then provides analyst with the few incidents fully investigated. In 30 days, 2 million signals in about 80 investigated incidents out. No rules written. Jazz won the 2026 CrowdStrike AWS and Nvidia Startup Accelerator from a nearly thousand applicants. See Melody in action at jazz.security-n2k. Hello everyone and welcome to the cyber wires research Saturday. I'm Dave Bittner and this is our weekly conversation with researchers and analysts tracking down the threats and vulnerabilities, solving some of the hard problems and protecting ourselves in a rapidly evolving cyber space. Thanks for joining us. One of our partner insurance carriers came to us with a client who had been encrypted by play.

And we took on the case from both a forensics and a ransomware. We took on the case of a friend of mine. That's Jean-Pierre Mouton, senior threat intelligence consultant at GuidePoint Security. The research we're discussing today is titled How Play Achieves Encryption. Let's start with play. We're going to start with the first one. We're going to start with the first one. We're going to start with the first one. We're going to start with the first one. Let's start with play itself. What distinguishes this ransomware operation from some of the other ransomware as a service models? Absolutely. So one of the major things that differentiates them from the ransomware as a service models is that they operate nominally or what they say themselves specifically on their dark web leak site is a closed model.

Meaning they actually have a singular team of operators as well as hands on keyboard hackers or however you would like to term them that work together from the instance of reaching a victim network all the way through negotiations and receiving payment. Whereas the ransomware as a service operators, you were what used to be ransom hub or key lin dragon forces a big one these days. They operate a core group of operators who maintain the encryption software and the data leak site itself, but they contract out the initial operations if you will against victim organizations to what they call affiliates or members who are not part of the core group. But do do operations on their behalf and they receive a cut of the final payment. So your research here follows an incident from earlier this year that pretty well followed plays established playbook pretty closely.

Can you walk us through that what typically happens when you're dealing with play specifically. So one of the things that we have noticed in all of our engagements that include play as the threat actor is they will typically start with an edge device that they'll compromise to gain access to the environment. Then they will dump credentials or use other avenues of achieving or retrieving credentials on the local machine in order to pivot to either more escalated privileges or other devices on the network. And then they'll move from there to full network compromise and push encryption to everything after they have xfiltrated data. In this case in particular, they actually went through the sonic wall, BPN process that this client had. And from there use the memicats, which is well known at this point in the industry, I believe tool in order to dump those credentials that were on the local machine.

And then they pivoted to an active directory where they staged everything on the system volume that shares across the entire network by everything I mean they staged their tooling they staged the data for x fill and then use that to push encryption across the entire network. Yeah, I thought one of the notable things in your research was that the earliest attacker attributed log on that you all tracked was about two and a half months before encryption. What does that tell us about the pace and the patience of these operators. Absolutely so play is one of those operators that we see with a longer 12 time meaning they stay on environment longer than most operators. And this is because they're very methodical in their approach to one breaching the network, but also staging and xfiltrating the data that they find interesting if you will. So what this tells us is unlike the dragon forces or the rass operators that we see out there.

They get in do deep reconnaissance to figure out where they need to go next identify what credentials they need to retrieve in order to flip their access to higher system or admin access and then they will do more reconnaissance figure out where the data is where the sensitive data is and then pull that together in a development process for For instance, in this case, they had a power show script that did most of the data pooling into the sysfool and perfor logs directory. And then once all of that is done, which takes a while as you can imagine to do it without getting caught on a regular basis, then they push encryption out. So it's more of their methodical approach compared to other operators that has led to them getting longer 12 times. Yeah, can we dig into that? I mean, what are some of the methods that they're using here to keep themselves from getting caught?

One of the main things that they're using to keep themselves from getting caught, which we do state specifically in the research is that they're using directories and locations on the network and on these endpoints where the monitoring is not as robust as you would expect on like your c drive or just your documents or your desktop or any of those where the actual virus scanners or endpoint detection and response systems, the EDRs are looking for that malicious scripts or malware to be. So they're using those paths, which are low scrutiny and then they're doing most of their work as far as maintaining access in those directories. And because it's low scrutiny, more times than not, they're actually not being scanned for the specific indicators that you would see for persistence on other operators.

Yeah, one of the evasion techniques here really caught my eye. It was an EDR evasion technique. They you point out that they use the victim's own Sentinel one removal utility walk us through how that works. Yeah, so every one of the EDRs and virus scanning tools that are out there, they want you to be able to uninstall their tool whenever you're moving to something else or just in general administrative procedures, for instance, when you're offlining a device that's end of life or something like that. So what they did was once they had gotten administrative access on those devices or across the network through the active directory, they use that standard application in order to remove Sentinel one itself and it was completely staged on the device by the developer. It comes with every package whenever you install Sentinel one and allowed them to just run the application for uninstalling and everything was gone as you would expect.

Now, is that a case where since you've given Sentinel one permission to install its app that it's assumed that you also has permission to uninstall. Yes, absolutely. Interesting. They also cleared out the Windows security logs from a defender's perspective. What is an event like that tell you? It tells me that they do not want to get caught. So whenever we're engaging in these digital forensics investigations, one of the main things that we're doing besides looking for what data has been accessed by the TA is also looking to get access to the T.A. So looking for indicators of how they accessed what they accessed when they accessed dwell time all of those sort of holistic data points so that we can track the TA what their tactics techniques procedures are on on keyboard themselves. This is one of those groups that actually goes out of their way in order to remove that capability for defenders because they do not want their tactics out there or anyone to be able to stop them.

And actually it goes against their ability to maintain anonymity and be on network and actually come across with those actions on keyboard within the breach in order for defenders to see those processes those tactics and put us in the table. So we're going to stop to them through alerting or your rules, etc. We'll be right back. Finding a doctor is hard enough finding the right doctor even harder. Someone who takes your insurance has an available appointment when you need one and feels like someone you can actually open up to. That's where Zock.com's in. Download the Zock.com app to search and compare doctors by specialty insurance and availability. Read real patient reviews find the right fit for you and book instantly because getting seen by the right doctor matters. Zock.com ready to be seen. Download the Zock.com app today. Every time your team deploys a new cloud workload or AI agent, another identity gets permitted access to your critical systems.

Legacy tools were built to manage human employees, leaving modern machine and AI access largely unmanaged. That's where IDIRA by Palo Alto Networks comes in. Human, machine, AI, one identity platform for all. IDIRA replaces permanent permissions with dynamic access so you can lock down every identity without slowing down your business. Secure every identity with IDIRA by Palo Alto Networks. Visit Palo Alto Networks slash IDIRA. Again, that's Palo Alto Networks.com slash IDIRA. Your heart can tell you a lot about your health. Apple Watch Series 12 measures your heart rate every five seconds with the most accurate heart rate sensing and awareable. So your vital zap now with heart rate variability can tell you when something is off. And your readiness score can let you know when to rest and when to push.

Here the story in every heartbeat with Apple Watch Series 12. The features described are for wellness purposes only and not for medical use. iPhone 11 or later require based on Apple conducted study of heart rate accuracy August 2026. Visit Apple.com slash Apple Watch Series 12. And now a word from our sponsor Spectorops today AI is rapidly adding non human and agentic identities to modern enterprise environments creating new trust relationships and attack paths. Bloodhound Enterprise helps defenders map attack paths across AWS and hybrid environments as one connected graph identify the choke points that matter most and bring trusted attack path intelligence into approved AI workflows with Bloodhound Hunter. See how Spectorops helps team secure the AI driven identity era at Spectorops.io.

Well, let's dig into the encryptor itself. How was play distributing and executing the ransomware across the environment. So one of the things that we actually see from other groups is they will use group policy objects, which is administrative controls on windows specifically to create a rule that pushes their encryptor out to the entire network that the GPO has access to play took this a separate way in that they decided to go for the sys fall or the system volume on the active directory. And stage the encryptor there what that means is active directory controls all of the devices on the network that is keyed into the active directory system itself. And the sys fall on the active directory is actually a shared volume that is pushed to every single device that is locked into that active directory.

So it appears on every single device on the network controlled by the active directory. I'm saying active directory a lot, but it's very important. So whenever they put their encryptor on that sys fall shared volume. It automatically pushed everything out to the network itself that's connected to the active directory without the need to modify any GPO policies or go through any of the other traditional admins that are connected to the network. So it's a very, I don't want to say novel, but unique way that they're encrypting the entire network without doing something that defenders are normally looking for because most defensive applications and procedures these days are looking for that GPO policy edit that will immediately alert to this is bad and it shouldn't be pushed out. And it was created specifically for this reason, which is just another one of those detection mechanisms that we look for specifically whenever we're doing our forensics investigations.

Yeah, there was an interesting forensic artifact that you highlighted. It was actually a failure that there was an encryptor crash dump. What was the value of that to you all as investigators. Absolutely. So this in particular gives us a unique look into what the encryptors doing and how they're staging it because the encryptor failed. There was a log produced on the end point that showed what the encryptor was trying to do where it was going next and what it was connecting to. So that gave us a little bit of a look into where the command and control was what live off living off the land evasion techniques they would potentially be using as well as what tools they had staged in order to support that entire mechanism itself. So we got a little bit more of a granular view into what they were attempting to accomplish and how they were attempting to do it compared to if that crash hadn't have happened because they were so meticulous in deleting all of the other logs.

Now there was a point where Windows defender detected some ransomware activity on a domain controller. What did that tell us describe that for me please. So whenever it comes to that action in particular what it tells us is that their encryptor itself is actually recognized by standard defender logic. Meaning it was recognized and it was blocked. However, that only occurred on one machine and that tells us that they there was an error outside of that failure. That we had just discussed that allowed this machine to not be effectively shut down when it comes to defender and it's just another data point as to how you can block it if everything operates correctly and they're not able to completely remove all of the security protocols that are in place. So in this case Windows defender flagging it was kind of an anomaly.

Yes, absolutely, especially with play compared to the activity. Yes, absolutely. No, no, no, I was essentially going to say the same thing you were going to compared to what normally happens or what happened on the rest of the environment. It was absolutely an anomaly and I don't think they expected it or were even aware that it happened. One of the things that you point out in the research is that plays consistency may create opportunities for behavioral detection. What are the strongest behaviors that defenders could hunt for before that encryption stage? Yeah, so previously I had mentioned that they were using sysfool as their way to push the encryptor out across the network. Specifically on the sysfool they were using a directory called perf logs. Now this perf logs is present on the active directory device under the sysfool but it's also present on every end point as well in your c directory or your c drive itself.

We identified I want to say correct me if I'm wrong here or don't quote me if I'm wrong here but somewhere around 11 artifacts within the engagement itself, all of which were staged in that perf logs directory and it's not usual for threat actors to use the same directory over and over again for staging their tools and ex filtration of data in that sort of directory. Mostly we'll see it happening in like the temp files under the user data or app data roaming temp those sorts of directories but consistently over three to four cases that we've worked since mid 2025 all of the data and all of the tools have been staged specifically in that perf logs directory. So that's a great indicator as far as how or where they're staging the data prior to ex filtration.

Well more broadly speaking, what are your recommendations then based on all this information you gathered, how should people best protect themselves against play. That is a very good question. We outline it kind of in the blog itself, but one of the things that we would recommend is tightening security access controls across your entire environment environment and that includes escalating EDR uninstallation capabilities to the highest level, additionally monitoring for any sort of proxy c2 behavior play likes to use system BC as their back door. If you will persistence mechanism on environment and monitoring for that specifically is effective because it uses the socks five proxy and most of the c2 that we're seeing nowadays. Don't use that as much anymore because it is so widely known as an indicator for abuse.

So that's one method as well as just focusing on behavioral detections in general to catch repeatable adversary playbooks and that like I said would be most of your remote access Trojans any cobalt strike tagged connections that are happening, which is widely distributed at this point and then additionally just looking for any changes in data manipulatory. As far as moving them staging them in certain directories on on the network itself, those are all great baseline indicators that you can start with and then move on to more robust things such as implementing your rules. Lisa has quite a robust amount of your rules established specifically for play that they published in their stop ransomware play. Log itself, so that would be a great resource to look for defensive recommendations.

And who do we suppose we're dealing with here, do we have any confidence in attribution. I would be remiss if I made any sort of conjecture regarding that we can we can obviously make guesses, but there's no way to really tell based on how they're connecting using the tour network to connect out to victim environments really off you skates. The connections themselves with the IPs used and everything so we can guess, but there's no way of knowing for sure. I think CISA wants to say that they are Russian in nature, but we at guide point cannot be sure of what they are specific. Our thanks to Jean-Pierre Mouton from Guide Point for joining us.

The research is titled How Play Achieves Incription. We'll have a link in the show notes. And that's Research Saturday brought to you by N2K CyberWire. We'd love to know what you think of this podcast, your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to cyberwire at n2k.com. This episode was produced by Liz Stokes, were mixed by Elliott Peltzmann and Trey Hester. Our executive producer is Jennifer Iben, Peter Kilpie is our publisher and I'm Dave Bittner. Thanks for listening. We'll see you back here next time. Find a doctor is hard enough finding the right doctor even harder. Someone who takes your insurance has an available appointment when you need one and feels like someone you can actually open up to. That's where Zoc.com's in. Download the Zoc.app to search and compare doctors by specialty insurance and availability. Read real-patient reviews.

Find the right fit for you and book instantly because getting seen by the right doctor matters. Zoc.com ready to be seen? Download the Zoc.app today. Hey everybody Dave here. I want to let you know about a special gathering hosted by Zimperium at the Spy Museum in Washington City. This invitation only event will bring together federal cybersecurity and technology leaders to discuss some of the most pressing challenges facing government today, including mobile security, mission resilience and the evolving threat landscape. I'm always grateful for opportunities to spend time with smart people doing important work for you. I'm also very proud of you. We're also very proud to be here today. We're also proud to be here today. I'm very proud to be here today. I hope to see some familiar faces there. If you are interested in attending you can request an invitation. You'll find more information in our show notes. Our thanks to Zimperium for sponsoring this event. We'll see you there.

Your heart can tell you a lot about your health. Apple Watch Series 12 measures your heart rate every 5 seconds with the most accurate heart rate sensing and awareable. So your vital zap now with heart rate variability can tell you when something is off. And your readiness score can let you know when to rest and when to push. Here the story in every heartbeat with Apple Watch Series 12. The features described are for wellness purposes only and not for medical use. iPhone 11 or later require based on Apple conducted study of heart rate accuracy August 2026 visit apple.com slash apple watch series 12.

More episodes

More from CyberWire Daily

View all episodes →