
Oct 3, 2026 · 25 min
Play ransomware turns trusted tools into attack infrastructure
Play to win, pay to lose. [Research Saturday]
Play’s months-long intrusions show how defenders can detect ransomware before encryption by tracking behavior, artifacts, and abused administrative access.
- 1Play operates as a closed ransomware team, managing intrusion, negotiation, and payment rather than relying on affiliates.
- 2Attackers combine edge-device compromise, credential theft, lateral movement, log clearing, and months of reconnaissance before encryption.
- 3Perflogs staging, SystemBC activity, and restricted EDR removal capabilities offer behavioral detection opportunities before systems are encrypted.
Don't miss
The investigation found Play using the victim’s own SentinelOne removal utility to disable endpoint protection and evade monitoring.
The brief
Jean-Pierre Mouton of GuidePoint Security examines a Play ransomware intrusion in which attackers spent months inside the victim environment before triggering widespread encryption.
Play’s closed operating model handles intrusion, negotiation, and payment as one operation, while its attack chain moves from edge-device compromise to credential theft and lateral movement.
The group abused trusted administrative tools, including a SentinelOne removal utility, then cleared Windows security logs to weaken detection and complicate reconstruction of its activity.
A crash dump exposed encryptor actions, command-and-control connections, and living-off-the-land techniques; Active Directory’s system volume helped stage the encryptor across endpoints.
The strongest defensive clues are behavioral: Perflogs staging, SystemBC proxy command and control, unusual EDR uninstallation, and other artifacts that can surface before encryption.