Hackers Exploit Windows Zero-Day to Unleash Play Ransomware Attacks

Hackers Exploit Windows Zero-Day to Unleash Play Ransomware Attacks

Play Ransomware Operators Exploit Windows Zero-Day for Stealth Intrusion and Credential Theft

An advanced cyber intrusion campaign attributed to the Play ransomware syndicate leveraged an unpatched Windows vulnerability (CVE-2025-29824) weeks before Microsoft issued a fix on April 8, 2025. This critical flaw in the Windows Common Log File System (CLFS) driver granted attackers the ability to escalate privileges and execute system-level commands undetected.

The exploit chain, uncovered by Symantec’s Threat Hunter Team, was used against a U.S.-based organization. Evidence suggests that a compromised Cisco ASA device may have served as the initial access vector. While no encryption payload was observed, attackers deployed Grixba—a bespoke credential-harvesting utility known to be used by Play affiliates (also tracked as Balloonfly or PlayCrypt).

Microsoft’s MSTIC and MSRC teams have attributed the attack to a threat actor labeled Storm-2460, which is known for its use of PipeMagic malware in ransomware-related campaigns. This group has widened its scope, targeting sectors ranging from IT and real estate in the U.S., to banking in Venezuela, retail in Saudi Arabia, and a software firm in Spain.

At the heart of the campaign lies a memory corruption flaw in the CLFS driver that enabled attackers to abuse a use-after-free condition. During execution, the threat actors dropped files under C:\ProgramData\SkyPDF, including a malicious DLL injected into the winlogon.exe process. This allowed credential extraction from LSASS via procdump.exe, new admin account creation, and persistence mechanisms to maintain access.

The vulnerability, rated 7.8 (High) on the CVSS scale, was among 121 issues resolved in Microsoft’s April 2025 Patch Tuesday. However, systems running Windows 11 version 24H2 are immune, thanks to newer built-in protections.

Play’s operators, active since mid-2022, have consistently refined their methods. Known for data theft prior to encryption (double extortion), they often disguise their tools as trusted security products—falsely mimicking brands like SentinelOne and Palo Alto Networks.

While zero-day exploitation by ransomware groups remains uncommon, this incident marks a significant escalation. The use of custom tooling and exploitation of privilege escalation vulnerabilities underscores the strategic value of such flaws in ransomware operations.

Security teams are urged to verify patch compliance and monitor for associated indicators of compromise (IoCs). The effectiveness of this attack emphasizes the critical need for rapid vulnerability management and strong identity protection.

Malicious Artifacts Linked to Play Ransomware Campaign (CVE-2025-29824)

Below is a detailed breakdown of files observed during the intrusion tied to the exploitation of the Windows CLFS zero-day vulnerability. These artifacts illustrate various stages of the attack chain, from initial exploitation to privilege escalation and data collection.

File Hash (SHA-256)FilenameRole in Attack ChainDetection / Threat Identifier
6030c438...gt_net.exeCustom infostealer used for credential harvestingIdentified as Infostealer.Grixba1
858efe4f...go.exeBinary leveraging CVE-2025-29824 to escalate privilegesNot yet classified
9c21adbc...clssrv.infMalicious DLL injected into winlogon.exeTagged as Exploit payload1
6d7374b4...cmdpostfix.batScript used to erase traces post-exploitationFlagged as Malicious batch file1
b2cba01a...servtask.batAutomates user creation and elevation of privilegesFlagged as Malicious batch file1
293b455b...paloaltoconfig.dllSpoofed DLL mimicking Palo Alto softwareClassified as Unknown malicious DLL1
af260c17...paloaltoconfig.exeRogue executable disguised as a Palo Alto Networks toolClassified as Unknown malicious EXE1
430d1364...1day.exeSuspected auxiliary tool used during exploitationClassified as Unknown malicious EXE1

More Articles & Posts