Cyber Threat Report: '#StopRansomware: Play Ransomware'

Report Author CISA
Publication Date 2023-12-18
Original Reporting Source
Related Intrusion Sets Play Ransomware Group
Identified CVEs CVE-2018-13379 , CVE-2022-41040 , CVE-2020-12812 , CVE-2022-41082

This is a Cybersecurity Advisory from CISA with US and international partners which outlines TTPs (tactics, techniques and procedures) and IoCs (indicators of compromise) associated with Play ransomware actors. According to the advisory, Play is a 'closed group' in order to "guarantee the secrecy of deals" and since October 2023, the FBI was "aware of approximately 300 affected entities allegedly exploited by the ransomware actors". The advisory also provides extensive mitigations for defending against this threat.

Cyber Threat Graph Context

Explore how this report relates to the wider threat graph

Mitigations to defend against the techniques in this report

Identified MITRE ATT&CK Techniques