CyberzSOC

Publication detail
← Back to advisories & guidance

#StopRansomware: Play Ransomware ↗ source

June 4, 2025 FBI Alert
Co-sealed by: ASD/ACSC, CISA, FBI

Summary

Tools Leveraged by Play Ransomware Actors AdFind Used to query and retrieve information from Active Directory. Bloodhound Used to query and retrieve information from Active Directory. GMER A software tool intended to be used for detecting and removing rootkits. An anti-malware and anti-virus program for the Microsoft Windows operating system. Play actors have accessed IOBit to disable antivirus software. PsExec A tool designed to run programs and execute commands on remote systems.

News Coverage

DateSourceArticle
2026-06-24 Kaspersky Securelist StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader CVE-2022-41040

Articles from the monitored vendor research blogs and security news feeds that reference a CVE cited in this publication, or name the campaign it covers. Coverage begins when feed monitoring started; earlier articles are not indexed.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2020-12812 9.8 Critical Fortinet FortiOS Fortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompted for the…
CVE-2018-13379 9.1 Critical Fortinet FortiOS Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system fil…
CVE-2024-57727 9.1 Critical SimpleHelp SimpleHelp SimpleHelp remote support software contains multiple path traversal vulnerabilities that allow unauthenticated remote attackers to download arbitrary…
CVE-2022-41040 8.8 High Microsoft Exchange Server Microsoft Exchange Server allows for server-side request forgery. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41082 which a…
CVE-2022-41082 8.0 High Microsoft Exchange Server Microsoft Exchange Server contains an unspecified vulnerability that allows for authenticated remote code execution. Dubbed "ProxyNotShell," this vul…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.