PlayBit, also known as luxor2008, is a Windows local privilege escalation exploit developer and seller associated with a series of 1-day kernel and win32k privilege-escalation exploits later used by multiple crimeware operations. The actor has been linked to exploits for CVE-2013-3660, CVE-2015-0057, CVE-2015-1701, CVE-2016-7255, and CVE-2018-8453. These exploit modules were subsequently used by malware and ransomware families including Dyre, Ramnit, Locky, LockCrypt, Maze, REvil, Evotob, and Neshta, indicating that PlayBit primarily operated as a supplier to downstream criminal customers rather than as a malware operator. PlayBit’s tradecraft shows stable engineering patterns across multiple exploit generations. Distinguishing characteristics include a custom hash-based import resolver, detailed operating-system fingerprinting, exploitability checks based on patch state, and kernel-address disclosure via Desktop Heap metadata exposed through Win32 client structures. The exploits commonly verified whether vulnerable win32k components had already been patched before proceeding. PlayBit also evolved kernel post-exploitation techniques over time, progressing from exploits without SMEP bypasses to kernel shellcode that disabled SMEP, and later to techniques that also cleared NX protections on the shellcode page. In attributed samples, leaked kernel pointers were used to build fake kernel objects, shape kernel memory, and locate kernel shellcode. The actor advertised Windows LPE 1-day exploits through underground forums and other public-facing channels, emphasizing broad Windows-version coverage, exploit reliability, and bypasses for mitigations and platform defenses. Reported pricing for these exploit packages was roughly in the mid-four- to low-five-figure range, consistent with commercial sale of reusable exploit components. PlayBit appears to have produced approximately one Windows LPE 1-day exploit per year for several years and later advertised additional Windows privilege-escalation exploits beyond the core set attributed here. PlayBit has also been connected to the Avatar Rootkit and EternalBlack tooling through shared implementation features and advertising evidence. Overall, the actor is best characterized as a financially motivated exploit merchant serving cybercriminal customers, with capabilities centered on Windows local privilege escalation, exploit reliability engineering, and post-exploitation enablement for malware operators.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Exploit developer and seller focused on Windows local privilege escalation 1-day exploits, later shifting toward logical vulnerabilities. Their exploits were used by multiple crimeware families and ransomware operators to elevate privileges before payload execution.
A separate exploit writer discussed for comparison, associated with several Windows LPE one-day exploits sold to malware operators including REvil.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.