Picus Security and Play Ransomware Group: Play Ransomware Masquerades as PsExec to Blend Into Legitimate Windows Administration

Picus Security and Play Ransomware Group: Play Ransomware Masquerades as PsExec to Blend Into Legitimate Windows Administration

Play Ransomware Exploits PsExec Disguise to Evade Detection

The Play ransomware group has adopted a deceptive tactic to blend into legitimate Windows administration activity, using a custom binary named PSexesvc.exe a near-identical mimic of Microsoft Sysinternals’ PsExec tool. This masquerading technique (MITRE ATT&CK T1036) allows attackers to execute lateral movement and payload deployment while evading suspicion, as the binary appears routine to defenders.

The malware has been observed staging tools and ransom notes in C:\Users\Public\Music</strong>, a seemingly innocuous directory that may go unnoticed during investigations. Play also leverages genuine PsExec and Windows Management Instrumentation (WMI) for lateral movement, complicating detection efforts by blending malicious activity with legitimate administrative workflows.

Recent findings from Picus Security highlight Play’s evasion prowess, ranking it as the least-prevented ransomware family in 2026 simulations, with only 13% of its attack techniques blocked by production security controls. The analysis, based on aggregated testing of real-world attack chains, underscores a critical gap: organizations often deploy endpoint, network, and logging tools but fail to detect the behavioral sequences ransomware operators exploit.

Key evasion techniques employed by Play and other low-prevention families include:

  • Obfuscated files (T1027): Encrypting payloads and configurations to bypass static scanners.
  • Security tool tampering: Disabling or modifying defenses.
  • Process injection, registry modification, and reflective code loading.
  • Signed binary abuse: Leveraging trusted executables for proxy execution.

For defenders, behavioral detection is critical. Security teams should prioritize monitoring for:

  • Remote execution (PsExec, WMI, PowerShell, RDP).
  • Suspicious service creation (e.g., PSexesvc launched from user-writable directories like Public\Music).
  • Abrupt service stoppages, Event Log clearing, or shadow-copy deletion.
  • Anomalous encryption activity in the same timeframe.

Mitigation recommendations align with CISA’s Play ransomware advisory, emphasizing:

  • Reducing remote-access exposure and patching internet-facing services.
  • Enforcing MFA for privileged and remote accounts.
  • Network segmentation and restricting administrative tools to approved hosts.
  • Offline backups to mitigate encryption impacts.

The broader takeaway: detection coverage on paper does not equal prevention in practice. Organizations must validate defenses against real-world attack chains, baselining approved workflows and correlating telemetry across endpoints, authentication logs, and network events. While banning PsExec outright is impractical, defenders should ensure its abuse is visible, attributable, and actionable.

Source: https://gbhackers.com/play-ransomware-minics-psexec/

Picus Security TPRM report: https://www.rankiteo.com/company/picus-security

Play Ransomware Group TPRM report: https://www.rankiteo.com/company/playcorp-studios

"id": "plapic1786364786",
"linkid": "playcorp-studios, picus-security",
"type": "Cyber Attack",
"date": "8/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'attack_vector': ['Lateral Movement',
                   'Process Injection',
                   'Signed Binary Abuse'],
 'data_breach': {'data_encryption': True, 'data_exfiltration': True},
 'description': 'The Play ransomware group has adopted a deceptive tactic to '
                'blend into legitimate Windows administration activity, using '
                'a custom binary named PSexesvc.exe—a near-identical mimic of '
                'Microsoft Sysinternals’ PsExec tool. This masquerading '
                'technique allows attackers to execute lateral movement and '
                'payload deployment while evading suspicion. The malware '
                'stages tools and ransom notes in C:\\Users\\Public\\Music\\, '
                'leverages genuine PsExec and WMI for lateral movement, and '
                'employs obfuscation, security tool tampering, and signed '
                'binary abuse to evade detection.',
 'impact': {'data_compromised': True},
 'lessons_learned': 'Detection coverage on paper does not equal prevention in '
                    'practice. Organizations must validate defenses against '
                    'real-world attack chains, baseline approved workflows, '
                    'and correlate telemetry across endpoints, authentication '
                    'logs, and network events.',
 'motivation': 'Financial Gain',
 'post_incident_analysis': {'corrective_actions': ['Validate defenses against '
                                                   'real-world attack chains.',
                                                   'Baseline approved '
                                                   'administrative workflows.',
                                                   'Correlate telemetry across '
                                                   'endpoints, authentication '
                                                   'logs, and network events.',
                                                   'Ensure abuse of '
                                                   'administrative tools '
                                                   '(e.g., PsExec) is visible, '
                                                   'attributable, and '
                                                   'actionable.'],
                            'root_causes': 'Failure to detect behavioral '
                                           'sequences of ransomware operators, '
                                           'reliance on static detection '
                                           'methods, and lack of correlation '
                                           'across security telemetry.'},
 'ransomware': {'data_encryption': True,
                'data_exfiltration': True,
                'ransomware_strain': 'Play'},
 'recommendations': ['Reduce remote-access exposure and patch internet-facing '
                     'services.',
                     'Enforce MFA for privileged and remote accounts.',
                     'Implement network segmentation and restrict '
                     'administrative tools to approved hosts.',
                     'Maintain offline backups to mitigate encryption impacts.',
                     'Monitor for remote execution (PsExec, WMI, PowerShell, '
                     'RDP), suspicious service creation, abrupt service '
                     'stoppages, Event Log clearing, or shadow-copy deletion.',
                     'Prioritize behavioral detection for anomalous encryption '
                     'activity.'],
 'references': [{'source': 'Picus Security'},
                {'source': 'CISA Play Ransomware Advisory'}],
 'response': {'enhanced_monitoring': 'Recommended',
              'network_segmentation': 'Recommended'},
 'threat_actor': 'Play Ransomware Group',
 'title': 'Play Ransomware Exploits PsExec Disguise to Evade Detection',
 'type': 'Ransomware'}
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.