Back to Resources

SentinelOne VS Play Ransomware – Prevention

Play Ransomware is a new type of malware seen starting in June 2022. The name “play” comes from the extension added to files once they have become encrypted by this ransomware family (i e., .play). This group usually initializes its activities with attack vectorization through vulnerabilities discovered in either FortiOS or other devices. Once inside a targeted environment, the group attempts to mask their activity and remain stealthy. For example, they rely heavily on the use of LOLBins. The group also uses commodity tools such as Anydesk, Netscan, and Advanced IP Scanner. The payloads are often spread through AD environments via GPO.
Play ransomware is one of several ransomware families using “intermittent encryption.” This is a method of partially encrypting specifically-sized chunks of data within files. This can assist in the evasion of ‘legacy’ malware detection systems.

지금 읽기

세계에서 가장 앞선 사이버 보안 플랫폼 경험하기

지능적인 자율형 사이버 보안 플랫폼이 현재와 미래의 조직을 어떻게 보호할 수 있는지 알아보세요.