The FBI, Cybersecurity and Infrastructure Security Agency and Australian Cyber Security Centre Dec. 18 released a warning about actions and tactics used by the Play ransomware group. The group has impacted a wide range of businesses and critical infrastructure in North America, South America and Europe since 2022, in addition to incidents in Australia in April and November this year. 

The cyber threat actors are presumed to be a closed group, designed to 鈥済uarantee the secrecy of deals,鈥 according to a statement on the group鈥檚 data leak website. Play ransomware actors use a double-extortion model, which encrypts systems after exfiltrating data; their ransom notes do not include an initial ransom demand or payment instructions, rather, victims are instructed to contact the threat actors via email. 

John Riggi, AHA鈥檚 national advisor for cybersecurity and risk, said, 鈥淭his ransomware group, like many others, has been observed to use compromised valid accounts to gain initial access through external-facing services such as Remote Desktop Protocol and virtual private networks. Once inside the network, they continue to exploit a variety of vulnerabilities in third-party software and chain them together to move laterally across an organization鈥檚 network, ultimately compromising unsecured administrative accounts. It is recommended that organizations apply the alert鈥檚 cited mitigations to limit potential hackers鈥 use of common system and network discovery techniques to reduce the risk of high-impact ransomware attacks.鈥 

For more information on this or other cyber and risk issues, contact Riggi at jriggi@aha.org. For the latest cyber and risk resources and threat intelligence, visit鈥aha.org/cybersecurity

Related News Articles

Headline
The Cybersecurity and Infrastructure Security Agency, Environmental Protection Agency, National Security Agency, FBI and international agencies Aug. 13鈥
Headline
The Department of Justice Aug. 11 announced a series of actions taken against the BlackSuit ransomware group, also known as 鈥淩oyal,鈥 including the disruption鈥
Headline
The FBI, Cybersecurity and Infrastructure Security Agency and international agencies July 29 released a joint advisory on recent tactics by the Scattered鈥
Headline
Microsoft July 22 released an update on the ongoing cyberattacks to SharePoint servers used within organizations, attributing the incidents to China-based鈥
Headline
The FBI, Cybersecurity and Infrastructure Security Agency, Department of Health and Human Services, and Multi-State Information Sharing and Analysis Center鈥
Headline
Microsoft July 19 issued an alert about active attacks from vulnerabilities targeting SharePoint servers used within organizations. The incidents have not鈥