Grixba is a custom .NET infostealer and reconnaissance tool associated with the Play ransomware group, also tracked as Playcrypt and by Symantec as Balloonfly. Public reporting places its use from at least 2022 onward in Play-linked intrusions, including cases where ransomware was not ultimately deployed. It is used early in the intrusion lifecycle for discovery, Active Directory reconnaissance, antivirus and security product detection, and broader environment enumeration.
High-confidence reporting describes Grixba as collecting information on remote systems, installed security products and software, browsing history, processes, sessions, users, computers in the domain, network routes, and other network information. Across reported versions, it enumerates systems via WMI, WinRM, Remote Registry, and Remote Services, and can scan for security, backup, remote administration, RMM, EDR, and AV products including products such as CrowdStrike, SentinelOne, Carbon Black, NinjaOne, Kaseya VSA, ConnectWise, IDrive, Synology C2, and Dropbox. Some reporting also states it harvests user credentials, cryptocurrency wallet data, and messaging application data. It has been described both as an infostealer and as a network-scanning/reconnaissance utility.
Earlier versions were built as monolithic .NET executables using Costura to embed dependencies into a single file. Those versions stored output in CSV files such as alive.csv, wm.csv, soft.csv, all_soft.csv, mount.csv, users.csv, remote_svc.csv, and cached_RDP.csv, then compressed results into export.zip using WinRAR. Later reporting describes a more modular version in which the executable GT_NET.exe, disguised as "SentinelOne Compatibility Wizard" version 1.1.6.0, worked with a companion file data.dat. That version required operator-supplied base64-encoded arguments and a base64-encoded XOR key to decrypt data.dat into inf_g.dll, which contained the scanning logic. Output was written to an SQLite database named ExportData.db with 18 tables and then stored in a password-protected archive named data.zip; the effective archive password depended on a hard-coded GUID value. Reporting also notes later staged variants and substantial changes in size, architecture, packaging, and output format across versions.
Grixba has command modes for broad scanning and log clearing. Reported functionality includes Scanall/Scan modes for environment enumeration and a Clr mode that deletes logs from local and remote systems. It has been observed using Windows Event Log APIs including EvtOpenLog and EvtClearLog, including deletion of WMI activity logs. Multiple analyses state that all examined versions retained core WMI/WinRM/Remote Registry/Remote Services enumeration behavior, log-clearing capability, and execution patterns involving ntdll.dll memory protection changes consistent with EDR unhooking behavior.
Operationally, Grixba has repeatedly been reported as dropped via RDP into C:\Users\Public\Music\ on compromised Windows servers. Reported filenames and artifacts include GT_NET.exe, data.dat, inf_g.dll, ExportData.db, data.zip, export.zip, and the CSV outputs noted above. One reported Play-linked sample communicated with 84.239.41.12, identified in the reporting as a Private Internet Access VPN exit node. A recurring mutex prefix, CPFATE_2704_v4.0.30319, has been observed in multiple versions.
Grixba is strongly associated with Play ransomware operations and has been cited in joint FBI/CISA/ACSC reporting as a Play tool used for Active Directory reconnaissance and antivirus detection. It has also appeared in reporting on Play-linked intrusions involving other tooling such as SystemBC, Cobalt Strike, PsExec, AdFind, Mimikatz, and WinPEAS. Targeting discussed in the supporting content is tied to Play activity broadly, which has affected organizations across North America, South America, and Europe, with reporting also highlighting impacts in the United States, Canada, and the United Kingdom and sectors including manufacturing, business, technology, retail, finance, medical, government, and critical infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Play Ransomware Attack Exploited CVE-2025-29824 as a 0-Day — ... leveraged CVE-2025-29824, a privilege escalation flaw in the Common Log File System (CLFS) driver that was patched by Microsoft last month. That said, no ransomware was actually deployed in the attack. However, Grixba... was put to use.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Grixba is a custom Infostealer developed by Play Ransomware Group using Costura (.NET tool for embedding dependencies into single executable), which is publicly disclosed in 2023 (but originally dates back to 2022).
Grixba is a custom Infostealer developed by Play Ransomware Group using Costura (.NET tool for embedding dependencies into single executable), which is publicly disclosed in 2023 (but originally dates back to 2022).
23 distinct techniques documented for this family, organized by ATT&CK tactic.
The v2 binary is named GT_NET.exe with PE version-info forged to display as “SentinelOne Compatibility Wizard” version 1.1.6.0. This mimics a known EDR vendor, making the process look legitimate in Task Manager and basic triage.
Detection implication in YARA rules, size thresholds, and file-name detections tuned for the v2 pattern (727 KB, ExportData.db, inf_g.dll, SentinelOne metadata) will silently miss v3. Defenders must pivot to behavioral detections...
RETAINED: Clr Mode—EvtOpenLog/EvtClearLog log wiping The Log-Clearing mode using the Windows Event Log APIs and WMI activity log wipe has been present in every version.
Grixba to collect information on remote systems, installed security products and software. Browsing history, processes and network information.
The v1.5 sample expands Grixba’s enumeration to include active host discovery across IP ranges... It maps everything on a compromised network before the Encryption phase—security tools, backup systems, remote management software, users, machines.
The v1.5 sample expands Grixba’s enumeration to include active host discovery across IP ranges, beyond just WMI enumeration. CISA labels it a “network scanner” alongside infostealer, indicating it can now aggressively identify reachable hosts and services.
It harvests information such as: Installed Software, User Credentials, Cryptocurrency Wallets, Messaging App Data. In short:- It maps everything on a compromised network before the Encryption phase—security tools, backup systems, remote management software, users, machines.
CISA’s published Snort detection rules for this hash trigger on a chain of 9 SMB-accessed web browser history paths... This means v1.5 added browser history collection—scanning for Chrome, Firefox, Edge, and Internet Explorer history databases accessible over SMB.
Upon access, Play actors conduct discovery using utilities like AdFind and Grixba for Active Directory reconnaissance
RETAINED: Core WMI/WinRM/Remote Registry/Remote Services Enumeration The foundational 4-API enumeration engine survives all versions intact.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom reconnaissance and infostealer tool used by the Play ransomware group to map compromised networks before encryption. It harvests installed software, user credentials, cryptocurrency wallets, messaging app data, and performs host/software enumeration via WMI/WinRM and related mechanisms.
Reconnaissance utility used to gather information in environments targeted by Play ransomware.
Grixba was mentioned as a reconnaissance utility used in a small number of cases to gather system, software, process, and network information.
A data gathering tool used for Active Directory reconnaissance and anti-virus detection in Play ransomware intrusions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.