AhnLab EDR을 활용한 Play 랜섬웨어 공격 사례 탐지

2025-01-02 Ahnlab 2. Privilege Escalation

https://asec.ahnlab.com/ko/85444/

Thumbnail for AhnLab EDR을 활용한 Play 랜섬웨어 공격 사례 탐지

AhnLab describes detection of a Play ransomware intrusion using EDR telemetry and notes that Play, also known as Balloonfly or PlayCrypt, has attacked more than 300 organizations since 2022. The report highlights double-extortion behavior through data theft before encryption and references Unit 42 reporting on collaboration between Play ransomware operators and Andariel. In the described case, Andariel used Sliver and DTrack to steal information, after which Play ransomware activity occurred through the same attack infrastructure.

Related Actors

First seen: Jul 2017
Last seen: May 2026

Related Reports

« Back