
Play to win, pay to lose. [Research Saturday]
Show notes
Today we are joined by Jean-Pierre Mouton, Senior Threat Intelligence Consultant at GuidePoint Security, discussing their work on "How Play Achieves Encryption." Play ransomware, also known as PlayCrypt, continues to target organizations across multiple sectors using a consistent double-extortion playbook that combines data theft with widespread encryption. A recent investigation details how the group gained access through a SonicWall VPN, moved laterally using tools such as Mimikatz and PsExec, exfiltrated sensitive data, and used the victim’s own SentinelOne uninstallation utility to disable endpoint protection. The findings highlight several behavioral indicators defenders can monitor, including tool staging through SYSVOL and SystemBC for command and control, event log clearing, and suspicious WinSCP activity.
The research and executive brief can be found here:
Learn more about your ad choices. Visit megaphone.fm/adchoices