Back to Resources

SentinelOne VS Play Ransomware – Prevention

Play Ransomware is a new type of malware seen starting in June 2022. The name “play” comes from the extension added to files once they have become encrypted by this ransomware family (i e., .play). This group usually initializes its activities with attack vectorization through vulnerabilities discovered in either FortiOS or other devices. Once inside a targeted environment, the group attempts to mask their activity and remain stealthy. For example, they rely heavily on the use of LOLBins. The group also uses commodity tools such as Anydesk, Netscan, and Advanced IP Scanner. The payloads are often spread through AD environments via GPO.
Play ransomware is one of several ransomware families using “intermittent encryption.” This is a method of partially encrypting specifically-sized chunks of data within files. This can assist in the evasion of ‘legacy’ malware detection systems.

Leggi ora

Scopri la piattaforma di sicurezza informatica più avanzata al mondo

Scopri cosa può fare la nostra piattaforma di sicurezza informatica autonoma intelligente per proteggere la tua azienda oggi e domani.