HackerFeeds
All ransomware groups

play

1,295 tracked victims
·first seen 2022-11-26·last activity 2026-08-06

Group profile

Initially observed in June 2022, the Play ransomware (a.k.a PlayCrypt) operates through double extortion, targeting numerous organizations in Latin America. Its Initial Access method is quite similar to other ransomwares, involving attacks such as Phishing, Exposed Services to the Internet, and Valid Account compromises.<br> <br> On April 19, 2023, the security company Symantec published two new tools developed by the Play group. These tools allow the malicious actor to enumerate and exfiltrate data from the internal network. The post mentions the following: 'Play threat actors use the .NET infostealer to enumerate software and services via WMI, WinRM, Remote Registry, and Remote Service. The malware checks for the existence of security and backup software, as well as remote administration tools and other programs, saving the information in .CSV files that are compressed into a .ZIP file for later manual exfiltration by threat actors.'Source: https://github.com/crocodyli/ThreatActors-TTPs

MITRE ATT&CK TTPs

TA0001

Initial Access

  • T1078Valid Accounts

    Compromised VPN credentials used to authenticate directly to victim networks.

  • T1078.002Valid Accounts: Domain Accounts

    [Play](https://attack.mitre.org/groups/G1040) has used valid domain accounts for access.(Citation: Trend Micro Ransomware Spotlight Play July 2023)

  • T1078.003Valid Accounts: Local Accounts

    [Play](https://attack.mitre.org/groups/G1040) has used valid local accounts to gain initial access.(Citation: Trend Micro Ransomware Spotlight Play July 2023)

  • T1133External Remote Services

    [Play](https://attack.mitre.org/groups/G1040) has used Remote Desktop Protocol (RDP) and Virtual Private Networks (VPN) for initial access.(Citation: CISA Play Ransomware Advisory December 2023)(Citation: Trend Micro Ransomware Spotlight Play July 2023)

  • T1190Exploit Public-Facing Application

    Play exploits vulnerabilities in Microsoft Exchange (ProxyNotShell CVE-2022-41040/CVE-2022-41082), FortiOS SSL VPN (CVE-2018-13379), and RDP to gain initial access.

TA0002

Execution

  • T1053.005Scheduled Task/Job: Scheduled Task

    Scheduled tasks used for payload persistence and execution across compromised hosts.

  • T1059Command and Scripting Interpreter

  • T1059.001Command and Scripting Interpreter: PowerShell

    PowerShell scripts used for payload execution and post-exploitation tooling deployment.

  • T1059.003Command and Scripting Interpreter: Windows Command Shell

    [Play](https://attack.mitre.org/groups/G1040) has used a batch script to remove indicators of its presence on compromised hosts.(Citation: Trend Micro Ransomware Spotlight Play July 2023)

TA0003

Persistence

  • T1078.002Valid Accounts: Domain Accounts

    [Play](https://attack.mitre.org/groups/G1040) has used valid domain accounts for access.(Citation: Trend Micro Ransomware Spotlight Play July 2023)

  • T1078.003Valid Accounts: Local Accounts

    [Play](https://attack.mitre.org/groups/G1040) has used valid local accounts to gain initial access.(Citation: Trend Micro Ransomware Spotlight Play July 2023)

  • T1133External Remote Services

    [Play](https://attack.mitre.org/groups/G1040) has used Remote Desktop Protocol (RDP) and Virtual Private Networks (VPN) for initial access.(Citation: CISA Play Ransomware Advisory December 2023)(Citation: Trend Micro Ransomware Spotlight Play July 2023)

TA0004

Privilege Escalation

  • T1078.002Valid Accounts: Domain Accounts

    [Play](https://attack.mitre.org/groups/G1040) has used valid domain accounts for access.(Citation: Trend Micro Ransomware Spotlight Play July 2023)

  • T1078.003Valid Accounts: Local Accounts

    [Play](https://attack.mitre.org/groups/G1040) has used valid local accounts to gain initial access.(Citation: Trend Micro Ransomware Spotlight Play July 2023)

TA0005

Defense Evasion

  • T1027Obfuscated Files or Information

    Play ransomware payloads are split into multiple parts to bypass AV scanning; parts reassembled on target systems.

  • T1027.010Obfuscated Files or Information: Command Obfuscation

    [Play](https://attack.mitre.org/groups/G1040) has used Base64-encoded PowerShell scripts for post exploit activities on compromised hosts.(Citation: Trend Micro Ransomware Spotlight Play July 2023)

  • T1070Indicator Removal

  • T1070.001Indicator Removal: Clear Windows Event Logs

    Windows event logs wiped to remove forensic evidence using wevtutil.

  • T1070.004Indicator Removal: File Deletion

    [Play](https://attack.mitre.org/groups/G1040) has used tools including [Wevtutil](https://attack.mitre.org/software/S0645) to remove malicious files from compromised hosts.(Citation: Trend Micro Ransomware Spotlight Play July 2023)

  • T1078.002Valid Accounts: Domain Accounts

    [Play](https://attack.mitre.org/groups/G1040) has used valid domain accounts for access.(Citation: Trend Micro Ransomware Spotlight Play July 2023)

  • T1078.003Valid Accounts: Local Accounts

    [Play](https://attack.mitre.org/groups/G1040) has used valid local accounts to gain initial access.(Citation: Trend Micro Ransomware Spotlight Play July 2023)

  • T1484Domain or Tenant Policy Modification

  • T1484.001Domain or Tenant Policy Modification: Group Policy Modification

  • T1562.001Disable or Modify Tools

    Security tools including Windows Defender and AV products disabled prior to encryption.

TA0006

Credential Access

  • T1003OS Credential Dumping

  • T1003.001OS Credential Dumping: LSASS Memory

    Mimikatz and similar tools used for LSASS memory dumping to harvest credentials.

  • T1003.003OS Credential Dumping: NTDS

    NTDS.dit extracted from domain controllers to obtain all domain account hashes.

  • T1552Unsecured Credentials

TA0007

Discovery

  • T1016System Network Configuration Discovery

  • T1018Remote System Discovery

    [Play](https://attack.mitre.org/groups/G1040) has used tools such as [AdFind](https://attack.mitre.org/software/S0552), [Nltest](https://attack.mitre.org/software/S0359), and [BloodHound](https://attack.mitre.org/software/S0521) to enumerate shares and hostnames on compromised networks.(Citation: Trend Micro Ransomware Spotlight Play July 2023)

  • T1046Network Service Discovery

    Network scanning tools used to enumerate hosts, services, and potential lateral movement targets.

  • T1057Process Discovery

    [Play](https://attack.mitre.org/groups/G1040) has used the information stealer Grixba to check for a list of security processes.(Citation: Trend Micro Ransomware Spotlight Play July 2023)

  • T1082System Information Discovery

    [Play](https://attack.mitre.org/groups/G1040) has leveraged tools to enumerate system information.(Citation: Trend Micro Ransomware Spotlight Play July 2023)

  • T1083File and Directory Discovery

    [Play](https://attack.mitre.org/groups/G1040) has used the Grixba information stealer to list security files and processes.(Citation: Trend Micro Ransomware Spotlight Play July 2023)

  • T1087.002Account Discovery: Domain Account

    Active Directory enumeration to identify privileged accounts and high-value targets.

  • T1518Software Discovery

  • T1518.001Software Discovery: Security Software Discovery

TA0008

Lateral Movement

  • T1021.001Remote Services: Remote Desktop Protocol

    RDP used for lateral movement across victim networks.

  • T1021.002Remote Services: SMB/Windows Admin Shares

    PsExec and SMB used to propagate payloads laterally.

  • T1570Lateral Tool Transfer

TA0009

Collection

  • T1560Archive Collected Data

  • T1560.001Archive Collected Data: Archive via Utility

    WinRAR used to compress and archive stolen data prior to exfiltration.

TA0010

Exfiltration

  • T1030Data Transfer Size Limits

    [Play](https://attack.mitre.org/groups/G1040) has split victims' files into chunks for exfiltration.(Citation: CISA Play Ransomware Advisory December 2023)(Citation: Trend Micro Ransomware Spotlight Play July 2023)

  • T1048Exfiltration Over Alternative Protocol

    WinSCP and Rclone used to exfiltrate data to actor-controlled infrastructure and cloud storage ahead of encryption.

TA0011

Command and Control

  • T1105Ingress Tool Transfer

    [Play](https://attack.mitre.org/groups/G1040) has used [Cobalt Strike](https://attack.mitre.org/software/S0154) to download files to compromised machines.(Citation: Trend Micro Ransomware Spotlight Play July 2023)

  • T1219Remote Access Software

    Cobalt Strike, SystemBC, and AnyDesk used as C2 frameworks for persistent access.

TA0040

Impact

  • T1486Data Encrypted for Impact

    Play ransomware uses AES-RSA hybrid encryption. Files appended with .play extension. Targets Windows and Linux/ESXi environments. Double extortion model with data published on Play leak site. Notable for NOT including ransom note in individual encrypted files — single note left at root of C: drive.

  • T1489Service Stop

    Database, mail, backup, and security services terminated before encryption to ensure maximum file access.

  • T1490Inhibit System Recovery

    Shadow copies deleted and Windows recovery disabled to prevent victim restoration of files.

  • T1657Financial Theft

TA0042

Resource Development

  • T1587.001Develop Capabilities: Malware

    [Play](https://attack.mitre.org/groups/G1040) developed and employ [Playcrypt](https://attack.mitre.org/software/S1162) ransomware.(Citation: Trend Micro Ransomware Spotlight Play July 2023)(Citation: CISA Play Ransomware Advisory December 2023)

  • T1588.002Obtain Capabilities: Tool

    [Play](https://attack.mitre.org/groups/G1040) has used multiple tools for discovery and defense evasion purposes on compromised hosts.(Citation: CISA Play Ransomware Advisory December 2023)

TA0112

Defense Impairment

  • T1685Disable or Modify Tools

    [Play](https://attack.mitre.org/groups/G1040) has used tools including GMER, IOBit, and PowerTool to disable antivirus software.(Citation: CISA Play Ransomware Advisory December 2023)(Citation: Trend Micro Ransomware Spotlight Play July 2023)

  • T1685.005Disable or Modify Tools: Clear Windows Event Logs

    [Play](https://attack.mitre.org/groups/G1040) has used tools to remove log files on targeted systems.(Citation: CISA Play Ransomware Advisory December 2023)(Citation: Trend Micro Ransomware Spotlight Play July 2023)

Recent victims

showing 50 of 1,295
DateWebsite / victimSectorCountry
2026-08-06
signatureservices.net
Signature Serviceswww.signatureservices.net
Professional Services
2026-08-06
gcatstx.com
GCATS Investmentswww.gcatstx.com
Financial ServicesUS
2026-08-06
platinum-grp.com
Platinum Groupwww.platinum-grp.com
ManufacturingUS
2026-08-04TechnologyUS
2026-08-04
preferredfinancial.com
Preferred Financial Groupwww.preferredfinancial.com
Financial ServicesUS
2026-07-27Retail & E-CommerceUS
2026-08-01
sigmaplasticsgroup.com
Sigma Plastics Groupwww.sigmaplasticsgroup.com
ManufacturingUS
2026-08-01
cambridgemgmt.net
Cambridge Managementwww.cambridgemgmt.net
Professional ServicesUS
2026-07-23
recordrentacar.com
Record Go Alquilerwww.recordrentacar.com
HospitalityES
2026-07-23
restaurantdepot.com
Restaurant Depotwww.restaurantdepot.com
Retail & E-CommerceUS
2024-03-06
tax-mt.com
The DeBrulerwww.tax-mt.com
Not FoundUS
2024-03-06Professional ServicesMT
2026-07-21
kreysler.com
Kreysler & Associateswww.kreysler.com
Professional ServicesUS
2026-07-16
betcorp.com
Boston Electric and Telephonewww.betcorp.com
TechnologyUS
2026-07-16Professional ServicesGB
2026-07-16ManufacturingNL
2026-07-16HealthcareAD
2026-07-16
sdr.se
Svensk Direktreklamwww.sdr.se
Professional ServicesSE
2026-07-07
preneed.net
Preneed Funeral Programswww.preneed.net
Retail & E-CommerceUS
2026-07-07
kblaa.com
Kevin Bao Lenguyenwww.kblaa.com
Not Found
2026-07-07
unitedinfrastructure.com
United Infrastructurewww.unitedinfrastructure.com
Energy & UtilitiesUS
2026-07-04
locatiarchitects.com
Locati Architectswww.locatiarchitects.com
Professional ServicesAU
2026-07-04
silvestriandassociates.com
Silvestri & Associates Insurancewww.silvestriandassociates.com
Financial ServicesUS
2026-06-30
wciboise.com
Western Constructionwww.wciboise.com
ManufacturingUS
2026-06-27Retail & E-CommerceUS
2026-06-27Agriculture and Food ProductionDE
2026-06-26
benchmarkinc.com
Benchmark Industrial Supplywww.benchmarkinc.com
Professional ServicesUS
2026-06-17Professional ServicesUS
2026-06-17
itc4u.com
Integrated Technologieswww.itc4u.com
Technology
2026-06-17TechnologyDE
2026-06-10
mundtinc.com
Mundt and Associateswww.mundtinc.com
Professional ServicesUS
2026-06-10
rainbowdistributorsusa.com
Rainbow Distributors USAwww.rainbowdistributorsusa.com
Retail & E-CommerceUS
2026-05-12TransportationGB
2026-06-04
urschel.com
Urschel Laboratorieswww.urschel.com
Agriculture and Food ProductionUS
2026-06-02
dallislawfirm.com
Dallis Law Firmwww.dallislawfirm.com
Professional ServicesUS
2026-05-29OtherUS
2026-05-29ManufacturingUS
2026-05-11
digitallgraphics.ca
Digitall Graphicswww.digitallgraphics.ca
TechnologyCA
2026-05-20
hightowernc.com
Hightower Communicationswww.hightowernc.com
TechnologyUS
2026-05-20Professional ServicesUS
2026-04-21Agriculture and Food ProductionNL
2026-05-19
rhcountryclub.com
Round Hill Country Clubwww.rhcountryclub.com
HospitalityUS
2026-05-15
legendnt.com
Legend Networking & Telecomwww.legendnt.com
TechnologyUS
2026-05-17Retail & E-CommerceUS
2026-05-01
dewaardtransport.nl
De Waard Transportwww.dewaardtransport.nl
TransportationNL
2026-05-05
z-h.de
Zuther Hautmannwww.z-h.de
ManufacturingDE
2026-04-20
imsmars.com
Infoworld Membership Systemswww.imsmars.com
Technology
2026-05-04
towncarinternational.com
Town Car Internationalwww.towncarinternational.com
TransportationUS
2026-04-28
northernmc.com
Northern Mechanical Contractorswww.northernmc.com
ManufacturingCA
2024-03-06ManufacturingUS