#balloonfly
By me @forbes.com: Don't get bitten by the Balloonfly. Great research from the Symantec threat hunter team.

#infosec

www.forbes.com/sites/daveyw...
Play Ransomware Zero-Day Attacks — US, Saudi Arabia Have Been Targeted
Play ransomware hackers exploited a Windows zero-day in multiple attacks — what you need to know.
www.forbes.com
May 8, 2025 at 10:07 AM
Notícia da SecurityOnline

"Desmascarando o Ransomware Play: Táticas, Técnicas e Estratégias de Mitigação" #bolhasec
Unmasking Play Ransomware: Tactics, Techniques, and Mitigation Strategies
Play ransomware, also known as Balloonfly or PlayCrypt, has emerged as a significant cyber threat since its discovery The post Unmasking Play Ransomware: Tactics, Techniques, and Mitigation Strategies appeared first on Cybersecurity News.
securityonline.info
January 10, 2025 at 8:16 AM
"Update, June 6, 2025: This story, originally published on June 5, has been updated with additional technical information regarding the Play ransomware threat, about which the FBI has issued a critical joint CISA security advisory, as well as an associated cybercrime group known as Balloonfly."
FBI Issues Critical Cyberattack Alert — Act Now As Victims Skyrocket
You have been warned — do not ignore this FBI ransomware advisory as the number of confirmed victims suddenly surges.
www.forbes.com
June 6, 2025 at 9:25 PM
#CyberSecurity #DataExfiltration #Doubleextortion Play Ransomware: A Rising Global Cybersecurity Threat:  

Play ransomware, also known as Balloonfly or PlayCrypt, has become a significant cybersecurity threat since its emergence in June 2022. Responsible for over 300 global attacks, this…
Play Ransomware: A Rising Global Cybersecurity Threat
  Play ransomware, also known as Balloonfly or PlayCrypt, has become a significant cybersecurity threat since its emergence in June 2022. Responsible for over 300 global attacks, this ransomware employs a double extortion model — stealing sensitive data…
dlvr.it
January 12, 2025 at 6:18 PM
Zero-Day CLFS Vulnerability (CVE-2025-29824) Exploited in Ransomware Attacks
Zero-Day CLFS Vulnerability (CVE-2025-29824) Exploited in Ransomware Attacks
A zero-day privilege escalation vulnerability (CVE-2025-29824) in Microsoft CLFS was exploited by Balloonfly (Play ransomware) before the official patch.
securityonline.info
May 7, 2025 at 4:25 PM
Windows 0-Day Vulnerability Exploited in Wild to Deploy Play ransomware
Windows 0-Day Vulnerability Exploited in Wild to Deploy Play ransomware
Threat actors linked to the Play ransomware operation exploited a zero-day vulnerability in Microsoft Windows prior to its patching on April 8, 2025. The vulnerability, tracked as CVE-2025-29824 , affects the Windows Common Log File System (CLFS) driver and allows attackers to elevate their privileges from standard user to full system access. The Symantec Threat Hunter Team reported that attackers affiliated with the Play ransomware group (also known as Balloonfly or PlayCrypt) targeted an unnamed organization in the United States, likely using a public-facing Cisco Adaptive Security Appliance (ASA) as an entry point. While no ransomware payload was deployed in the discovered intrusion, the attackers utilized a custom information-stealing tool called Grixba, which has been previously associated with the Play ransomware operation. Microsoft’s Threat Intelligence Center (MSTIC) and Security Response Center (MSRC) identified that the exploitation activity has been attributed to a threat group called Storm-2460, which deploys the PipeMagic malware in ransomware campaigns. The targets included organizations in the United States’ information technology (IT) and real estate sectors, Venezuela’s financial sector, a Spanish software company, and Saudi Arabia’s retail sector. Exploitation of Windows 0-Day Vulnerability “Ransomware threat actors value post-compromise elevation of privilege exploits because these could enable them to escalate initial access into privileged access,” Microsoft stated in its security advisory. The vulnerability, which received a CVSS score of 7.8 (High), was addressed as part of Microsoft’s April 2025 Patch Tuesday updates, which fixed a total of 121 vulnerabilities. Technical analysis revealed that the exploitation involved a sophisticated attack chain. The vulnerability resides in the CLFS kernel driver and allows attackers to exploit a use-after-free condition. During the exploit execution, attackers created files in the path C:\ProgramData\SkyPDF, including a DLL that was injected into the winlogon.exe process. This allowed them to extract credentials from LSASS memory using tools like the Sysinternals procdump.exe, create new administrator users, and establish persistence. The Play ransomware group, active since June 2022, is known for deploying double-extortion tactics, where sensitive data is exfiltrated prior to encryption. The group has previously developed custom tools like Grixba, which have been disguised as legitimate security software, including fake SentinelOne and Palo Alto Networks applications. Researchers noted that while ransomware actors rarely use zero-day vulnerabilities, this signals an escalation in their capabilities. Organizations are strongly advised to apply the security updates released on April 8, 2025, especially for systems running vulnerable versions of Windows. Microsoft specifically mentioned that customers running Windows 11 version 24H2 are not affected by this vulnerability due to security mitigations already in place. This incident highlights the continuing evolution of ransomware tactics and the importance of prompt patching, especially for vulnerabilities that enable privilege escalation, which are critical components in ransomware attack chains. IoC’s Here’s the table of Indicators of Compromise (IoCs) linked to the Play ransomware campaign exploiting CVE-2025-29824: Hash Filename Description Detection/Malware Name 6030c4381b8b5d5c5734341292316723a89f1bdbd2d10bb67c4d06b1242afd05 gt_net.exe Grixba infostealer tool Infostealer.Grixba1 858efe4f9037e5efebadaaa70aa8ad096f7244c4c4aeade72c51ddad23d05bfe go.exe CVE-2025-29824 exploit binary N/A1 9c21adbcb2888daf14ef55c4fa1f41eaa6cbfbe20d85c3e1da61a96a53ba18f9 clssrv.inf DLL injected into winlogon.exe Exploit payload1 6d7374b4f977f689389c7155192b5db70ee44a7645625ecf8163c00da8828388 cmdpostfix.bat Artifact cleanup script Malicious batch file1 b2cba01ae6707ce694073018d948f82340b9c41fb2b2bc49769f9a0be37071e1 servtask.bat Privilege escalation/user creation script Malicious batch file1 293b455b5b7e1c2063a8781f3c169cf8ef2b1d06e6b7a086b7b44f37f55729bd paloaltoconfig.dll Masqueraded Palo Alto Networks tool Unknown malicious DLL1 af260c172baffd0e8b2671fd0c84e607ac9b2c8beb57df43cf5df6e103cbb7ad paloaltoconfig.exe Masqueraded Palo Alto Networks tool Unknown malicious EXE1 430d1364d0d0a60facd9b73e674faddf63a8f77649cd10ba855df7e49189980b 1day.exe Suspected exploit-related utility Unknown malicious EXE1 Tax Scams Are Getting Smarter – Check Malicious Domains With Domain Research Suite The post Windows 0-Day Vulnerability Exploited in Wild to Deploy Play ransomware appeared first on Cyber Security News .
cybersecuritynews.com
May 7, 2025 at 12:32 PM
Play/Balloonflyランサムウェアグループ、Windowsゼロデイ脆弱性CVE-2025-29824を悪用 – 米国組織を標的に
innovatopia.jp/cyber-securi...
Play/Balloonflyランサムウェアグループ、Windowsゼロデイ脆弱性CVE-2025-29824を悪用 – 米国組織を標的に - イノベトピア
2025年5月8日、セキュリティ企業Symantec(ブロードコムの一部門)は、Playランサムウェアグループ
innovatopia.jp
May 8, 2025 at 1:11 AM
Windowsのゼロデイ脆弱性を悪用するPlayランサムウェアが実環境で展開される

共通ログ ファイル システム (CLFS) ドライバーの修正済み Windows ゼロデイ脆弱性 (CVE-2025-29824) は、2025 年 4 月 8 日に公開される前に、Play ランサムウェア操作に関連する攻撃で悪用されました。

この脆弱性は、clfs.sys カーネル ドライバーの解放後使用状態による権限昇格を可能にするもので、Play ランサムウェアの背後にいるサイバー犯罪グループ Balloonfly が米国組織への侵入を試みている際に武器として利用しました。
Play Ransomware Deployed in the Wild Exploiting Windows 0-Day Vulnerability
Patched Windows zero-day vulnerability (CVE-2025-29824) in the CLFS driver was exploited in attacks linked to the Play ransomware operation.
gbhackers.com
May 9, 2025 at 9:19 PM
ランサムウェア攻撃者は権限昇格ゼロデイを悪用

Play ランサムウェア攻撃に関与した攻撃者は、米国の組織に対する攻撃中に、ゼロデイ権限昇格の脆弱性を展開しました。この攻撃は、2025 年 4 月 8 日に共通ログ ファイル システム ドライバー (clfs.sys) における Windows のゼロデイ権限昇格の脆弱性 ( CVE-2025-29824 ) が公開され、修正プログラムが適用される前に発生しました。

侵入時にランサムウェアのペイロードは展開されませんでしたが、攻撃者は、Play ランサムウェア攻撃の背後にいる攻撃者Balloonfly に関連付けられたカスタム ツール...
Ransomware Attackers Leveraged Privilege Escalation Zero-day
Exploit used by Play-linked attackers targets the CVE-2025-29824 zero-day vulnerability patched on April 8.
www.security.com
May 9, 2025 at 9:11 PM
Playランサムウェアを使用するBalloonflyグループは、WindowsのCLFSドライバの特権昇格のゼロデイ脆弱性(CVE-2025-29824)2025年4月8日の修正前に悪用
なお、複数グループが同一脆弱性を使っていた点からも、ゼロデイ情報の裏マーケットの可能性が示唆されています。
www.security.com/threat-intel...
Ransomware Attackers Leveraged Privilege Escalation Zero-day
Exploit used by Play-linked attackers targets the CVE-2025-29824 zero-day vulnerability patched on April 8.
www.security.com
May 8, 2025 at 3:15 PM