← Back to feed
general GBHackers

Play Ransomware Masquerades as PsExec to Blend Into Legitimate Windows Administration

GBHackers • • Microsoft

Play ransomware is using a familiar Windows-administration disguise to reduce suspicion during intrusions: a custom service binary named PSexesvc.exe.

T1021
Read the full story GBHackers →

Related Coverage

general Co-creator of Empire Market dark web marketplace given 40-year sentence The Record · Oct 10 general FBI Arrests Founder of Ransomware Negotiation Firm Krebs on Security · Oct 10 general OpenAI Fires 3 Safety Researchers in Dispute Over AI Risks SecurityWeek · Oct 9