By Davey Winder, Senior Contributor Jan 11, 2025,08:43am EST
As new reports confirm that the ransomware cyberattack threat is far from a thing of the past, and even the likes of LockBit which had been thought to have disbanded following law enforcement disruption has now confirmed a date for a return to action is just weeks away. Now, a new analysis has revealed the danger posed by ongoing Play ransomware attacks. Here’s what you need to know.
The Play Ransomware Attack Threat
Analysts from AhnLab have published an in-depth look at the Play ransomware threat, first detected in 2022 and responsible for more than 300 successful attacks worldwide from then on. Play ransomware, which the researchers warned remains actively in use, is so-called due to the use of a “.PLAY” extension given to the files it encrypts.
Linked to Andariel, a North Korean state-sponsored attack group that is part of the Democratic People’s Republic of Korea’s “Reconnaissance General Bureau,” Play would appear to be an integral part of its cyber arsenal.
The methods by which these ransomware actors gain initial access to target networks include, the researchers said, “abusing valid accounts or attacking vulnerabilities in exposed services.” Microsoft ProxyNotShell Exchange Server vulnerabilities (CVE-2022-41040, CVE-2022-41082) and those in Fortinet’s FortiOS (CVE-2020-12812, CVE-2018-13379) are known to have been used. So, ensuring that these are properly patched is vital.
Play attackers, the AhnLab report confirmed, gather information on active systems and port numbers of running services through port scanning methods. Active Directory information is then collected, and “attack paths for privilege escalation” identified using specialist tools. By using this privilege escalation to provide admin access, the attackers can then steal credential information to be used for lateral movement and ultimate domain environment control.
It’s not only state-sponsored Play attacks that are an ongoing concern to organizations everywhere, ransomware-as-a-service and double-extortion ransom tactics of all criminal gangs need to be considered. The Federal Bureau Of Investigation has warned users to be alert to the risk and recommended mitigation methods, including:
- Install updates for operating systems, software and firmware as soon as they are released.
- Require phishing-resistant, non SMS-based multi-factor authentication.
- Educate users to both recognize and report phishing attempts.
Play ransomware manages to evade detection using legitimate tools such as Process Hacker to disable security products where possible. “Many of the tools used in the process are not malware strains,” AhnLab researchers said, “but those that can also be used for legitimate purposes.” All making detection harder. Finally, a Play ransomware attack will encrypt an organization’s systems but also, as is the norm these days, exfiltrate information first so as to leverage extortion demands via leak sites.
This story was originally featured on Forbes.com

Davey Winder
Senior Contributor | Cybersecurity
Follow me on Twitter or LinkedIn. Check out my website or some of my other work here.
Davey has spent more than 30 years as a freelance technology journalist. The author of 25 published books, Davey’s work has appeared in The Times, The Sunday Times, The Guardian, The Observer, PC Pro, The Register, Infosecurity Magazine, SC Magazine, IT Pro and TechFinitive to name but a very few.
Along the way, he has picked up a bunch of awards from his peers, including:
‘Most Educational Content’ (2021 European Blogger of the Year Awards) – ‘Cyber Writer of the Year’ (2020 Security Serious Awards) – ‘Enigma Award’ (2011 BT Security Awards) – ‘Security Journalist of the Year’ (2010 BT Security Awards) – ‘Security Journalist of the Year’ (2008 BT Security Awards) – ‘Security Journalist of the Year’ (2006 BT Security Awards) – ‘Technology Journalist of the Year’ (1996 BT Technology Journalism Awards)
Businessiraq.com is committed to supporting the growth and development of Iraq’s economy. As part of this commitment, the website provides a range of resources and tools to help businesses succeed in the country. These resources include industry reports, market research, and business guides, all of which are designed to help businesses navigate the Iraqi market and identify new opportunities. By providing access to these resources, Businessiraq.com helps businesses to make informed decisions, mitigate risks, and achieve their goals.
Discover Iraq’s Premier Business Directory and B2B Marketplace | businessiraq.com – Your Ultimate Gateway to Iraqi Market Success Transform your business journey in Iraq with businessiraq.com, the Middle East’s most sophisticated and comprehensive business intelligence platform. Our AI-powered trilingual directory (Arabic-English-Kurdish) seamlessly connects 100,000+ verified Iraqi companies with global investors and partners, offering unparalleled access to Iraq’s lucrative sectors including Oil & Gas, Construction, Technology, and emerging industries. Powered by real-time BoldData analytics and enhanced with blockchain verification, our platform delivers essential tools for success: live tender alerts, interactive business mapping across Iraq’s governorates, secure trade finance solutions, and detailed company profiles with verified financial metrics. International businesses benefit from our exclusive features, including customized market entry strategies, regulatory compliance guidance, and virtual B2B matchmaking services, while local Iraqi enterprises gain powerful digital exposure to global markets. With daily-updated business news, investment guides, and market analysis covering Baghdad, Basra, Erbil, and beyond, businessiraq.com maintains the highest standards of data security (ISO 27001 certified) and user privacy (GDPR compliant). Join over 50,000 monthly active users already leveraging our platform’s 95% success rate in B2B connections, and unlock exclusive benefits including priority listings, personalized market intelligence reports, and VIP access to Iraq’s largest business networking events. Start your success story in Iraq’s rapidly growing economy today at businessiraq.com, where verified opportunities meet innovative solutions. Keywords integrated: Iraq business directory, Iraqi companies database, B2B marketplace Iraq, Baghdad business listings, Kurdistan companies, Iraq tender platform, Iraqi business intelligence, Middle East B2B portal, Iraq market entry guide, Iraqi investment opportunities, Iraq company verification, Arabic business directory, Iraq trade directory, Iraqi suppliers database, business in Iraq, Iraq economic news, Iraq market analysis, Iraqi business registration, Iraq company formation, Middle East business platform