{"id":48314,"date":"2022-09-06T00:00:00","date_gmt":"2022-09-06T00:00:00","guid":{"rendered":"urn:uuid:3f8a1737-07cb-8a44-814a-ebfc09a545fd"},"modified":"2022-09-06T00:00:00","modified_gmt":"2022-09-06T00:00:00","slug":"play-ransomwares-attack-playbook-unmasks-it-as-another-hive-affiliate-like-nokoyawa","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/play-ransomwares-attack-playbook-unmasks-it-as-another-hive-affiliate-like-nokoyawa\/","title":{"rendered":"Play Ransomware&#8217;s Attack Playbook Unmasks it as Another Hive Affiliate like Nokoyawa"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/i\/play-ransomware's-attack-playbook-unmasks-it-as-another-hive-affiliate-like-nokoyawa\/PlayHiveNokoyawa-banner.jpg\"><\/p>\n<div><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/i\/play-ransomware's-attack-playbook-unmasks-it-as-another-hive-affiliate-like-nokoyawa\/PlayHiveNokoyawa-banner.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p><b>Initial Access<\/b><\/p>\n<p>Play\u2019s ransomware actors commonly gain initial access through valid accounts that have been reused across multiple platforms, have previously been exposed, or were obtained through illegal means. This includes Virtual Private Network (VPN) accounts, not just domain and local accounts. Exposed RDP servers are also abused to establish a foothold. Another technique Play ransomware uses is the exploitation of the FortiOS vulnerabilities <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2018-13379\" target=\"_blank\" rel=\"noopener\">CVE-2018-13379<\/a> and <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2020-12812\" target=\"_blank\" rel=\"noopener\">CVE-2020-12812<\/a>.<\/p>\n<p>CVE-2018-13379 is a path traversal vulnerability in the FortiOS SSL VPN web portal that allows an unauthenticated attacker to download OS system files through specially crafted HTTP resource requests.&nbsp; On the other hand, CVE-2020-12812 is an improper-authentication vulnerability in SSL VPN in FortiOS, which allows a user to log in without being prompted for FortiToken, the second factor of authentication, if they changed the case of their username.<\/p>\n<p><b>Execution<\/b><\/p>\n<p>We observed Play ransomware\u2019s usage of scheduled tasks and PsExec during its execution phase.&nbsp;Another one of Play\u2019s techniques involves the creation of a GPO, as GPOs are able to control many user and machine settings in the AD. The GPO deploys a scheduled task across the AD environment, and the task executes the ransomware at a specific date and time.&nbsp;&nbsp;<\/p>\n<p>The ransomware also uses batch files to execute PsExec, a legitimate Windows tool in the SysInternals suite. This tool\u2019s ability to execute processes on other systems allows the rapid spread of the ransomware and assists Play in its reconnaissance activities.<\/p>\n<p><b>Persistence<\/b><\/p>\n<p>After the Play ransomware actors gain initial access through valid accounts, they will continue to use these accounts as a persistence mechanism. If Remote Desktop Protocol (RDP) access is disabled in a victim\u2019s system, the malicious actors will enable it by executing \u201cnetsh\u201d commands so that they can establish inbound connections within a victim\u2019s system. The ransomware executable is dropped in the Domain Controller shared folders (NETLOGON or SYSVOL) and is run by a scheduled task\/PsExec, after which encryption of the victim\u2019s files takes place.&nbsp;<\/p>\n<p><b>Privilege Escalation<\/b><\/p>\n<p>Play ransomware uses <a href=\"https:\/\/attack.mitre.org\/software\/S0002\/\" target=\"_blank\" rel=\"noopener\">Mimikatz<\/a> to extract high privileges credentials from memory. Afterward, the ransomware will add accounts to privileged groups, one of which is the Domain Administrators group. It performs vulnerability enumeration through <a href=\"https:\/\/github.com\/carlospolop\/PEASS-ng\" target=\"_blank\" rel=\"noopener\">Windows Privilege Escalation Awesome Scripts<\/a> (WinPEAS), a script that searches for possible local privilege escalation paths.<\/p>\n<p><b>Defense Evasion<\/b><\/p>\n<p>The ransomware uses tools such as <a href=\"https:\/\/processhacker.sourceforge.io\/\" target=\"_blank\" rel=\"noopener\">Process Hacker<\/a>, <a href=\"http:\/\/www.gmer.net\/\" target=\"_blank\" rel=\"noopener\">GMER<\/a>, <a href=\"https:\/\/www.iobit.com\/pt\/index.php\" target=\"_blank\" rel=\"noopener\">IOBit,<\/a> and <a href=\"https:\/\/www.softpedia.com\/get\/Antivirus\/Removal-Tools\/ithurricane-PowerTool.shtml\" target=\"_blank\" rel=\"noopener\">PowerTool<\/a> to disable antimalware and monitoring solutions. It covers its tracks using the Windows built-in tool wevtutil or a batch script, which will remove indicators of its presence, such as logs in Windows Event Logs or malicious files. It disables Windows Defender protection capabilities through PowerShell or command prompt. The PowerShell scripts that Play ransomware uses, like Cobalt Strike beacons (Cobeacon) or Empire agents, are encrypted in Base64.<\/p>\n<p><b>Credential Access<\/b><\/p>\n<p>Play ransomware also uses Mimikatz to dump credentials. The tool can be dropped directly on the target host or executed as a module through a command-and-control (C&amp;C) application like Empire or Cobalt Strike. We also observed the malware\u2019s use of the Windows tool Task Manager to dump the LSASS process from memory.<\/p>\n<p><b>Discovery<\/b><\/p>\n<p>During the discovery phase, the ransomware actors collect more details about the AD environment. We\u2019ve observed that AD queries for remote systems have been performed by different tools, such as <a href=\"https:\/\/attack.mitre.org\/software\/S0552\/\" target=\"_blank\" rel=\"noopener\">ADFind<\/a>, <a href=\"https:\/\/docs.microsoft.com\/en-us\/previous-versions\/windows\/it-pro\/windows-server-2012-r2-and-2012\/cc731935(v=ws.11)\" target=\"_blank\" rel=\"noopener\">Microsoft Nltest<\/a>, and <a href=\"https:\/\/attack.mitre.org\/software\/S0521\/\" target=\"_blank\" rel=\"noopener\">Bloodhound<\/a>. Enumeration of system information such as hostnames, shares, and domain information were also performed by the threat actor.<\/p>\n<p><b>Lateral Movement<\/b><\/p>\n<p>Play ransomware may use different tools to move laterally across a victim\u2019s system:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\"><a href=\"https:\/\/attack.mitre.org\/software\/S0154\/\" target=\"_blank\" rel=\"noopener\">Cobalt Strike SMB beacon<\/a> is used as a C&amp;C beacon, a method of lateral movement, and a tool for downloading and executing files<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><a href=\"https:\/\/news.sophos.com\/en-us\/2020\/12\/16\/systembc\/\" target=\"_blank\" rel=\"noopener\">SystemBC<\/a>, a SOCKS5 proxy bot that acts as a backdoor with the ability to communicate over TOR, is used for backdooring mechanisms<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><a href=\"https:\/\/attack.mitre.org\/software\/S0363\/\" target=\"_blank\" rel=\"noopener\">Empire<\/a> is an open-source post-exploitation framework used to conduct Play ransomware\u2019s post-exploitation activity<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><a href=\"https:\/\/github.com\/gentilkiwi\/mimikatz\" target=\"_blank\" rel=\"noopener\">Mimikatz<\/a> is used to dump credentials and gain domain administrator access on victim networks to conduct lateral movement.&nbsp;<\/span><\/li>\n<\/ul>\n<p><b>Exfiltration<\/b><\/p>\n<p>A victim\u2019s data is often split into chunks instead of whole files prior to its exfiltration, an approach that Play ransomware may use to avoid triggering network data transfer. The ransomware actors use WinSCP, an SFTP client and FTP client for Microsoft Windows. They also use WinRAR to compress the files in .RAR format for later exfiltration. We were able to identify a web page developed in PHP that is used to receive the exfiltrated files.<\/p>\n<p><b>Impact<\/b><\/p>\n<p>As mentioned earlier, after the ransomware encrypts a file, it adds the extension \u201c.play\u201d to that file. A ransom note, <i>ReadMe.txt<\/i>, is created in the hard drive root (C:). In all the cases we investigated, the ransom notes contained an email address following this format: <i>[seven random characters]@gmx[.]com<\/i>.&nbsp;&nbsp;<\/p>\n<p> Read More <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/22\/i\/play-ransomware-s-attack-playbook-unmasks-it-as-another-hive-aff.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Play is a new ransomware that takes a page out of Hive and Nokoyawa&#8217;s playbook. The many similarities among them indicate that Play, like Nokoyawa, may be a Hive affiliate. Read More HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[61],"tags":[9510,9539,9509],"class_list":["post-48314","post","type-post","status-publish","format-standard","hentry","category-trendmicro","tag-trend-micro-research-articles-news-reports","tag-trend-micro-research-ransomware","tag-trend-micro-research-research"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Play Ransomware&#039;s Attack Playbook Unmasks it as Another Hive Affiliate like Nokoyawa 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/play-ransomwares-attack-playbook-unmasks-it-as-another-hive-affiliate-like-nokoyawa\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Play Ransomware&#039;s Attack Playbook Unmasks it as Another Hive Affiliate like Nokoyawa 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/play-ransomwares-attack-playbook-unmasks-it-as-another-hive-affiliate-like-nokoyawa\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2022-09-06T00:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/i\/play-ransomware's-attack-playbook-unmasks-it-as-another-hive-affiliate-like-nokoyawa\/PlayHiveNokoyawa-banner.jpg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/play-ransomwares-attack-playbook-unmasks-it-as-another-hive-affiliate-like-nokoyawa\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/play-ransomwares-attack-playbook-unmasks-it-as-another-hive-affiliate-like-nokoyawa\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Play Ransomware&#8217;s Attack Playbook Unmasks it as Another Hive Affiliate like Nokoyawa\",\"datePublished\":\"2022-09-06T00:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/play-ransomwares-attack-playbook-unmasks-it-as-another-hive-affiliate-like-nokoyawa\\\/\"},\"wordCount\":828,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/play-ransomwares-attack-playbook-unmasks-it-as-another-hive-affiliate-like-nokoyawa\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.trendmicro.com\\\/content\\\/dam\\\/trendmicro\\\/global\\\/en\\\/research\\\/22\\\/i\\\/play-ransomware's-attack-playbook-unmasks-it-as-another-hive-affiliate-like-nokoyawa\\\/PlayHiveNokoyawa-banner.jpg\",\"keywords\":[\"Trend Micro Research : Articles, News, Reports\",\"Trend Micro Research : Ransomware\",\"Trend Micro Research : Research\"],\"articleSection\":[\"TrendMicro\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/play-ransomwares-attack-playbook-unmasks-it-as-another-hive-affiliate-like-nokoyawa\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/play-ransomwares-attack-playbook-unmasks-it-as-another-hive-affiliate-like-nokoyawa\\\/\",\"name\":\"Play Ransomware's Attack Playbook Unmasks it as Another Hive Affiliate like Nokoyawa 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/play-ransomwares-attack-playbook-unmasks-it-as-another-hive-affiliate-like-nokoyawa\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/play-ransomwares-attack-playbook-unmasks-it-as-another-hive-affiliate-like-nokoyawa\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.trendmicro.com\\\/content\\\/dam\\\/trendmicro\\\/global\\\/en\\\/research\\\/22\\\/i\\\/play-ransomware's-attack-playbook-unmasks-it-as-another-hive-affiliate-like-nokoyawa\\\/PlayHiveNokoyawa-banner.jpg\",\"datePublished\":\"2022-09-06T00:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/play-ransomwares-attack-playbook-unmasks-it-as-another-hive-affiliate-like-nokoyawa\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/play-ransomwares-attack-playbook-unmasks-it-as-another-hive-affiliate-like-nokoyawa\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/play-ransomwares-attack-playbook-unmasks-it-as-another-hive-affiliate-like-nokoyawa\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.trendmicro.com\\\/content\\\/dam\\\/trendmicro\\\/global\\\/en\\\/research\\\/22\\\/i\\\/play-ransomware's-attack-playbook-unmasks-it-as-another-hive-affiliate-like-nokoyawa\\\/PlayHiveNokoyawa-banner.jpg\",\"contentUrl\":\"https:\\\/\\\/www.trendmicro.com\\\/content\\\/dam\\\/trendmicro\\\/global\\\/en\\\/research\\\/22\\\/i\\\/play-ransomware's-attack-playbook-unmasks-it-as-another-hive-affiliate-like-nokoyawa\\\/PlayHiveNokoyawa-banner.jpg\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/play-ransomwares-attack-playbook-unmasks-it-as-another-hive-affiliate-like-nokoyawa\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Trend Micro Research : Articles, News, Reports\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/trend-micro-research-articles-news-reports\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Play Ransomware&#8217;s Attack Playbook Unmasks it as Another Hive Affiliate like Nokoyawa\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Play Ransomware's Attack Playbook Unmasks it as Another Hive Affiliate like Nokoyawa 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/play-ransomwares-attack-playbook-unmasks-it-as-another-hive-affiliate-like-nokoyawa\/","og_locale":"en_US","og_type":"article","og_title":"Play Ransomware's Attack Playbook Unmasks it as Another Hive Affiliate like Nokoyawa 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/play-ransomwares-attack-playbook-unmasks-it-as-another-hive-affiliate-like-nokoyawa\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2022-09-06T00:00:00+00:00","og_image":[{"url":"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/i\/play-ransomware's-attack-playbook-unmasks-it-as-another-hive-affiliate-like-nokoyawa\/PlayHiveNokoyawa-banner.jpg","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/play-ransomwares-attack-playbook-unmasks-it-as-another-hive-affiliate-like-nokoyawa\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/play-ransomwares-attack-playbook-unmasks-it-as-another-hive-affiliate-like-nokoyawa\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Play Ransomware&#8217;s Attack Playbook Unmasks it as Another Hive Affiliate like Nokoyawa","datePublished":"2022-09-06T00:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/play-ransomwares-attack-playbook-unmasks-it-as-another-hive-affiliate-like-nokoyawa\/"},"wordCount":828,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/play-ransomwares-attack-playbook-unmasks-it-as-another-hive-affiliate-like-nokoyawa\/#primaryimage"},"thumbnailUrl":"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/i\/play-ransomware's-attack-playbook-unmasks-it-as-another-hive-affiliate-like-nokoyawa\/PlayHiveNokoyawa-banner.jpg","keywords":["Trend Micro Research : Articles, News, Reports","Trend Micro Research : Ransomware","Trend Micro Research : Research"],"articleSection":["TrendMicro"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/play-ransomwares-attack-playbook-unmasks-it-as-another-hive-affiliate-like-nokoyawa\/","url":"https:\/\/www.threatshub.org\/blog\/play-ransomwares-attack-playbook-unmasks-it-as-another-hive-affiliate-like-nokoyawa\/","name":"Play Ransomware's Attack Playbook Unmasks it as Another Hive Affiliate like Nokoyawa 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/play-ransomwares-attack-playbook-unmasks-it-as-another-hive-affiliate-like-nokoyawa\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/play-ransomwares-attack-playbook-unmasks-it-as-another-hive-affiliate-like-nokoyawa\/#primaryimage"},"thumbnailUrl":"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/i\/play-ransomware's-attack-playbook-unmasks-it-as-another-hive-affiliate-like-nokoyawa\/PlayHiveNokoyawa-banner.jpg","datePublished":"2022-09-06T00:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/play-ransomwares-attack-playbook-unmasks-it-as-another-hive-affiliate-like-nokoyawa\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/play-ransomwares-attack-playbook-unmasks-it-as-another-hive-affiliate-like-nokoyawa\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/play-ransomwares-attack-playbook-unmasks-it-as-another-hive-affiliate-like-nokoyawa\/#primaryimage","url":"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/i\/play-ransomware's-attack-playbook-unmasks-it-as-another-hive-affiliate-like-nokoyawa\/PlayHiveNokoyawa-banner.jpg","contentUrl":"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/i\/play-ransomware's-attack-playbook-unmasks-it-as-another-hive-affiliate-like-nokoyawa\/PlayHiveNokoyawa-banner.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/play-ransomwares-attack-playbook-unmasks-it-as-another-hive-affiliate-like-nokoyawa\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Trend Micro Research : Articles, News, Reports","item":"https:\/\/www.threatshub.org\/blog\/tag\/trend-micro-research-articles-news-reports\/"},{"@type":"ListItem","position":3,"name":"Play Ransomware&#8217;s Attack Playbook Unmasks it as Another Hive Affiliate like Nokoyawa"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/48314","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=48314"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/48314\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=48314"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=48314"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=48314"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}