Play Ransomware Operators Exploit Windows Zero-Day for Stealth Intrusion and Credential Theft
An advanced cyber intrusion campaign attributed to the Play ransomware syndicate leveraged an unpatched Windows vulnerability (CVE-2025-29824) weeks before Microsoft issued a fix on April 8, 2025. This critical flaw in the Windows Common Log File System (CLFS) driver granted attackers the ability to escalate privileges and execute system-level commands undetected.
The exploit chain, uncovered by Symantec’s Threat Hunter Team, was used against a U.S.-based organization. Evidence suggests that a compromised Cisco ASA device may have served as the initial access vector. While no encryption payload was observed, attackers deployed Grixba—a bespoke credential-harvesting utility known to be used by Play affiliates (also tracked as Balloonfly or PlayCrypt).
Microsoft’s MSTIC and MSRC teams have attributed the attack to a threat actor labeled Storm-2460, which is known for its use of PipeMagic malware in ransomware-related campaigns. This group has widened its scope, targeting sectors ranging from IT and real estate in the U.S., to banking in Venezuela, retail in Saudi Arabia, and a software firm in Spain.
At the heart of the campaign lies a memory corruption flaw in the CLFS driver that enabled attackers to abuse a use-after-free condition. During execution, the threat actors dropped files under C:\ProgramData\SkyPDF, including a malicious DLL injected into the winlogon.exe process. This allowed credential extraction from LSASS via procdump.exe, new admin account creation, and persistence mechanisms to maintain access.
The vulnerability, rated 7.8 (High) on the CVSS scale, was among 121 issues resolved in Microsoft’s April 2025 Patch Tuesday. However, systems running Windows 11 version 24H2 are immune, thanks to newer built-in protections.
Play’s operators, active since mid-2022, have consistently refined their methods. Known for data theft prior to encryption (double extortion), they often disguise their tools as trusted security products—falsely mimicking brands like SentinelOne and Palo Alto Networks.
While zero-day exploitation by ransomware groups remains uncommon, this incident marks a significant escalation. The use of custom tooling and exploitation of privilege escalation vulnerabilities underscores the strategic value of such flaws in ransomware operations.
Security teams are urged to verify patch compliance and monitor for associated indicators of compromise (IoCs). The effectiveness of this attack emphasizes the critical need for rapid vulnerability management and strong identity protection.
Malicious Artifacts Linked to Play Ransomware Campaign (CVE-2025-29824)
Below is a detailed breakdown of files observed during the intrusion tied to the exploitation of the Windows CLFS zero-day vulnerability. These artifacts illustrate various stages of the attack chain, from initial exploitation to privilege escalation and data collection.
| File Hash (SHA-256) | Filename | Role in Attack Chain | Detection / Threat Identifier |
|---|---|---|---|
6030c438... | gt_net.exe | Custom infostealer used for credential harvesting | Identified as Infostealer.Grixba1 |
858efe4f... | go.exe | Binary leveraging CVE-2025-29824 to escalate privileges | Not yet classified |
9c21adbc... | clssrv.inf | Malicious DLL injected into winlogon.exe | Tagged as Exploit payload1 |
6d7374b4... | cmdpostfix.bat | Script used to erase traces post-exploitation | Flagged as Malicious batch file1 |
b2cba01a... | servtask.bat | Automates user creation and elevation of privileges | Flagged as Malicious batch file1 |
293b455b... | paloaltoconfig.dll | Spoofed DLL mimicking Palo Alto software | Classified as Unknown malicious DLL1 |
af260c17... | paloaltoconfig.exe | Rogue executable disguised as a Palo Alto Networks tool | Classified as Unknown malicious EXE1 |
430d1364... | 1day.exe | Suspected auxiliary tool used during exploitation | Classified as Unknown malicious EXE1 |




