The Play ransomware gang has exploited a high-severity Windows Common Log File System flaw in zero-day attacks to gain SYSTEM privileges and deploy malware on compromised systems. The vulnerability, tracked as CVE-2025-29824, was tagged by Microsoft as exploited in a limited number of attacks and patched during last month's Patch Tuesday. "The targets include organizations in the information technology (IT) and real estate sectors of the United States, the financial sector in Venezuela, a Spanish software company, and the retail sector in Saudi Arabia," Microsoft said in April. Microsoft linked these attacks to the RansomEXX ransomware gang, saying the attackers installed the PipeMagic backdoor malware, which was used to drop the CVE-2025-29824 exploit, deploy ransomware payloads, and ransom notes after encrypting files. Since then, Symantec's Threat Hunter Team has also found evidence linking them to the Play ransomware-as-a-service operation, saying the attackers deployed a CVE-2025-29824 zero-day privilege escalation exploit after breaching a U.S. organization's network. "Although no ransomware payload was deployed in the intrusion, the attackers deployed the Grixba infostealer, which is a custom tool associated with Balloonfly, the attackers behind the Play ransomware operation," Symantec said. "Balloonfly is a cybercrime group that has been active since at least June 2022 and uses the Play ransomware (also known as PlayCrypt) in attacks." The Grixba custom network-scann...
Play ransomware exploited Windows logging flaw in zero-day attacks
BleepingComputer
·Sergiu Gatlan
·Published May 7, 2025
·Updated
Affected Software
2 affected components
Microsoft Windows
Microsoft Windows Common Log File System
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses how the Play ransomware gang exploited a Windows logging flaw for zero-day attacks.
2
What security implications are discussed?
The exploitation of a critical vulnerability allowed attackers to gain SYSTEM privileges and deploy malware.
3
What vulnerability is being discussed in the article?
The vulnerability is tracked as CVE-2025-29824, related to the Windows Common Log File System.
4
What software is affected by this ransomware attack?
The affected software includes Microsoft Windows and the Windows Common Log File System.
5
Who is behind the zero-day attacks mentioned in the article?
The zero-day attacks are attributed to the Play ransomware gang.