AhnLab EDR을 활용한 Play 랜섬웨어 공격 사례 탐지
2025-01-02 • Ahnlab • 2. Privilege Escalation •
AhnLab describes detection of a Play ransomware intrusion using EDR telemetry and notes that Play, also known as Balloonfly or PlayCrypt, has attacked more than 300 organizations since 2022. The report highlights double-extortion behavior through data theft before encryption and references Unit 42 reporting on collaboration between Play ransomware operators and Andariel. In the described case, Andariel used Sliver and DTrack to steal information, after which Play ransomware activity occurred through the same attack infrastructure.
Related Actors
Related Reports
2025-01-01 •
90% Match
#Andariel
#Ransomware
#Play
#T1046
#T1219
#T1562.001
#T1486
#T1018
#T1657
#T1003.001
#T1048.003
#T1560.001
#T1033
#T1087.002
#T1570
#T1069.001
#T1069.002
#T1572
#T1615
#T1482
Shares tags: Andariel, Ransomware, Play • Same author: Ahnlab • Published within a week
Shares tag: Andariel • Same author: Ahnlab • Published within a month
Shares tag: Andariel • Same author: Ahnlab • Published within a month
Shares tag: Andariel • Same author: Ahnlab • Published within a month
Shares tag: Andariel • Same author: Ahnlab • Published within a month
Shares tag: Andariel • Published within a month