Grixba is a custom Windows .NET infostealer and reconnaissance utility associated with the Play ransomware operation, also tracked as PlayCrypt and linked by some vendors to the Balloonfly cluster. It is used during post-compromise phases to map victim environments, identify defensive controls and backup infrastructure, and prepare follow-on actions such as privilege escalation, lateral movement, data theft, and ransomware deployment.
Grixba is primarily known for broad enterprise discovery. It enumerates users, computers, installed software, services, processes, sessions, browser history, network information, and remote systems across Windows domains. Reported implementations use WMI, WinRM, Remote Registry, and Remote Services to collect information from local and remote hosts, and include scanning logic aimed at identifying antivirus, EDR, backup, remote administration, and other security-relevant products. Some observed versions also support active host discovery across IP ranges and collection of additional environment data useful for targeting high-value systems.
The malware has also demonstrated defense-evasion functionality. Documented variants include a mode for clearing local and remote Windows event logs through native event log APIs, including removal of WMI activity logs. Multiple analyzed versions reportedly altered memory protections in ntdll.dll during execution, behavior assessed as consistent with unhooking or EDR-evasion tradecraft. Operators have also used deceptive branding in some builds to masquerade as legitimate security software.
Grixba has evolved substantially across versions. Earlier builds were monolithic .NET executables that exported reconnaissance results to CSV files and compressed them for operator retrieval. Later builds adopted a more modular design in which encrypted components were decoded at runtime to provide scanning functionality, and some versions stored results in a SQLite database inside a password-protected archive. Despite these packaging changes, core behavior remained focused on reconnaissance, software inventorying, and environmental assessment. Public reporting also notes use of Costura in earlier builds to embed dependencies into a single executable.
The malware is closely tied to Play ransomware intrusions and has been repeatedly observed alongside tooling such as SystemBC and common administrative or offensive utilities used by Play actors. It has been deployed in incidents where ransomware was not ultimately executed, indicating value as a standalone pre-encryption intelligence-gathering tool. Victimology associated with Play spans multiple sectors and regions, with reporting frequently highlighting enterprise and server environments. Grixba is therefore best understood as a purpose-built infostealer for ransomware operations, optimized for domain-wide reconnaissance, security product discovery, and preparation of subsequent intrusion stages on Windows networks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Play Ransomware Attack Exploited CVE-2025-29824 as a 0-Day — ... leveraged CVE-2025-29824, a privilege escalation flaw in the Common Log File System (CLFS) driver that was patched by Microsoft last month. That said, no ransomware was actually deployed in the attack. However, Grixba... was put to use.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Grixba is a custom Infostealer developed by Play Ransomware Group using Costura (.NET tool for embedding dependencies into single executable), which is publicly disclosed in 2023 (but originally dates back to 2022).
Grixba is a custom Infostealer developed by Play Ransomware Group using Costura (.NET tool for embedding dependencies into single executable), which is publicly disclosed in 2023 (but originally dates back to 2022).
25 distinct techniques documented for this family, organized by ATT&CK tactic.
The v2 binary is named GT_NET.exe with PE version-info forged to display as “SentinelOne Compatibility Wizard” version 1.1.6.0. This mimics a known EDR vendor, making the process look legitimate in Task Manager and basic triage.
Clr mode deletes the logs from local and remote computers... It uses the APIs "EvtOpenLog" and "EvtClearLog" to delete the logs and deletes the WMI activity logs from the event source "Microsoft-Windows-WMI-Activity".
It uses the APIs "EvtOpenLog" and "EvtClearLog" to delete the logs and deletes the WMI activity logs from the event source "Microsoft-Windows-WMI-Activity".
Grixba to collect information on remote systems, installed security products and software. Browsing history, processes and network information.
The first tool found by researchers at Symantec... was Grixba (Infostealer.Grixba), which is a network-scanning tool used to enumerate all users and computers in the domain.
Grixba (Infostealer.Grixba), which is a network-scanning tool used to enumerate all users and computers in the domain.
The threat actors use the .NET infostealer to enumerate software and services via WMI, WinRM, Remote Registry, and Remote Services.
CISA’s published Snort detection rules for this hash trigger on a chain of 9 SMB-accessed web browser history paths... This means v1.5 added browser history collection—scanning for Chrome, Firefox, Edge, and Internet Explorer history databases accessible over SMB.
Upon access, Play actors conduct discovery using utilities like AdFind and Grixba for Active Directory reconnaissance
No Anti-Sandbox or No-Debug Capability... It executes identically whether it is run on a victim server or in a Cuckoo sandbox.
RETAINED: Core WMI/WinRM/Remote Registry/Remote Services Enumeration The foundational 4-API enumeration engine survives all versions intact.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom reconnaissance and infostealer tool used by the Play ransomware group to map compromised networks before encryption. It harvests installed software, user credentials, cryptocurrency wallets, messaging app data, and performs host/software enumeration via WMI/WinRM and related mechanisms.
Reconnaissance utility used to gather information in environments targeted by Play ransomware.
Grixba was mentioned as a reconnaissance utility used in a small number of cases to gather system, software, process, and network information.
A data gathering tool used for Active Directory reconnaissance and anti-virus detection in Play ransomware intrusions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.