Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The September 2024 intrusion analyzed by The DFIR Report showed artifacts associated with Play, RansomHub and DragonForce ransomware operations. The report assessed that the operator was most likely an affiliate working across multiple groups, but it did not identify a person or establish a confirmed operator identity. Data was exfiltrated; the attacker was evicted before deploying ransomware.

What connects the intrusion to three ransomware operations?

The connection comes from one intrusion analysis, published by The DFIR Report on September 8, 2025. The report compares tools and artifacts observed during the incident with activity associated with the three operations. These clues differ in directness and do not, on their own, prove that one named actor controlled all three operations.

Operation Observed clue What the clue supports—and what it does not prove
Play The intruder used Grixba, a reconnaissance tool associated with Play. This is a tool-based association. CISA’s joint Play advisory also describes Play actors using Grixba for network enumeration. It does not identify the individual behind the intrusion.
RansomHub The intrusion involved the Betruger backdoor, which The DFIR Report links to RansomHub affiliates; the report also notes other tools and staging behavior associated with RansomHub activity. This supports a connection to tooling and behavior reported among RansomHub affiliates, not a confirmed identity or proof that every artifact had a single owner.
DragonForce A NetScan output file found in the intrusion appeared to contain data from a company reportedly listed on DragonForce’s leak site. This is an indirect artifact-based clue. An apparent match to a leak-site victim is not, by itself, proof that the intrusion operator belonged to DragonForce.

The report also identifies shared tools and techniques across the three operation columns. Overlap can inform an operational assessment, but it is not proof that the groups share ownership or that a particular person operated them.

What happened during the September 2024 intrusion?

According to The DFIR Report’s incident analysis, the intrusion began when a user executed a malicious file impersonating DeskSoft’s EarthTime application. The report describes subsequent activity involving SectopRAT, SystemBC and Betruger, followed by reconnaissance, lateral movement, data compression and transfer.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The report records 3,861 internal DNS queries during execution of one Grixba version and 1,373 internal DNS A-record queries during execution of another. These are counts tied to the two tool executions—not numbers of victims.

The attacker was evicted before ransomware deployment, but the report says data had already been exfiltrated. It does not establish which ransomware operation, if any, would have been used for a final encryption stage.

Does the report identify the threat actor?

No. The DFIR Report’s conclusion is qualified: it assesses that the operator was “most likely” an affiliate operating across multiple ransomware groups. It does not name the operator or provide a publicly established personal or cluster identity. That is an evidence-based assessment from an intrusion analysis, not a confirmed law-enforcement attribution.

The distinction matters: tools can be reused, shared or adopted by different operators, and an artifact that resembles data from a leak-site victim can suggest a link without establishing who created or possessed it. The three clues should therefore be read together as support for the report’s assessment, not as three equally conclusive identifications.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What does official Play guidance recommend?

A joint advisory from CISA, the FBI and the Australian Signals Directorate’s Australian Cyber Security Centre, revised June 4, 2025, provides broader context on Play ransomware and defensive measures. It reports that the FBI was aware of approximately 900 entities allegedly exploited by Play ransomware actors as of May 2025. That is an approximate awareness figure in the advisory, not a verified census and not a count associated with the September 2024 intrusion.

The advisory says: “Organizations should take the following actions today to mitigate cyber threats from Play ransomware.” Its recommendations include:

  • Remediate known exploited vulnerabilities and keep software and firmware current.
  • Enable multifactor authentication, particularly for webmail, VPNs and accounts that access critical systems.
  • Maintain offline backups and prepare a recovery plan.

These are general recommendations from the Play advisory; they are not findings about the affected organization’s controls in The DFIR Report’s incident. See the CISA, FBI and ASD ACSC joint Play ransomware advisory for the full guidance.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.