play
Group profile
Initially observed in June 2022, the Play ransomware (a.k.a PlayCrypt) operates through double extortion, targeting numerous organizations in Latin America. Its Initial Access method is quite similar to other ransomwares, involving attacks such as Phishing, Exposed Services to the Internet, and Valid Account compromises.<br> <br> On April 19, 2023, the security company Symantec published two new tools developed by the Play group. These tools allow the malicious actor to enumerate and exfiltrate data from the internal network. The post mentions the following: 'Play threat actors use the .NET infostealer to enumerate software and services via WMI, WinRM, Remote Registry, and Remote Service. The malware checks for the existence of security and backup software, as well as remote administration tools and other programs, saving the information in .CSV files that are compressed into a .ZIP file for later manual exfiltration by threat actors.'Source: https://github.com/crocodyli/ThreatActors-TTPs
MITRE ATT&CK TTPs
Initial Access
T1078Valid Accounts
Compromised VPN credentials used to authenticate directly to victim networks.
T1078.002Valid Accounts: Domain Accounts
[Play](https://attack.mitre.org/groups/G1040) has used valid domain accounts for access.(Citation: Trend Micro Ransomware Spotlight Play July 2023)
T1078.003Valid Accounts: Local Accounts
[Play](https://attack.mitre.org/groups/G1040) has used valid local accounts to gain initial access.(Citation: Trend Micro Ransomware Spotlight Play July 2023)
T1133External Remote Services
[Play](https://attack.mitre.org/groups/G1040) has used Remote Desktop Protocol (RDP) and Virtual Private Networks (VPN) for initial access.(Citation: CISA Play Ransomware Advisory December 2023)(Citation: Trend Micro Ransomware Spotlight Play July 2023)
T1190Exploit Public-Facing Application
Play exploits vulnerabilities in Microsoft Exchange (ProxyNotShell CVE-2022-41040/CVE-2022-41082), FortiOS SSL VPN (CVE-2018-13379), and RDP to gain initial access.
Execution
T1053.005Scheduled Task/Job: Scheduled Task
Scheduled tasks used for payload persistence and execution across compromised hosts.
T1059Command and Scripting Interpreter
T1059.001Command and Scripting Interpreter: PowerShell
PowerShell scripts used for payload execution and post-exploitation tooling deployment.
T1059.003Command and Scripting Interpreter: Windows Command Shell
[Play](https://attack.mitre.org/groups/G1040) has used a batch script to remove indicators of its presence on compromised hosts.(Citation: Trend Micro Ransomware Spotlight Play July 2023)
Persistence
T1078.002Valid Accounts: Domain Accounts
[Play](https://attack.mitre.org/groups/G1040) has used valid domain accounts for access.(Citation: Trend Micro Ransomware Spotlight Play July 2023)
T1078.003Valid Accounts: Local Accounts
[Play](https://attack.mitre.org/groups/G1040) has used valid local accounts to gain initial access.(Citation: Trend Micro Ransomware Spotlight Play July 2023)
T1133External Remote Services
[Play](https://attack.mitre.org/groups/G1040) has used Remote Desktop Protocol (RDP) and Virtual Private Networks (VPN) for initial access.(Citation: CISA Play Ransomware Advisory December 2023)(Citation: Trend Micro Ransomware Spotlight Play July 2023)
Privilege Escalation
T1078.002Valid Accounts: Domain Accounts
[Play](https://attack.mitre.org/groups/G1040) has used valid domain accounts for access.(Citation: Trend Micro Ransomware Spotlight Play July 2023)
T1078.003Valid Accounts: Local Accounts
[Play](https://attack.mitre.org/groups/G1040) has used valid local accounts to gain initial access.(Citation: Trend Micro Ransomware Spotlight Play July 2023)
Defense Evasion
T1027Obfuscated Files or Information
Play ransomware payloads are split into multiple parts to bypass AV scanning; parts reassembled on target systems.
T1027.010Obfuscated Files or Information: Command Obfuscation
[Play](https://attack.mitre.org/groups/G1040) has used Base64-encoded PowerShell scripts for post exploit activities on compromised hosts.(Citation: Trend Micro Ransomware Spotlight Play July 2023)
T1070Indicator Removal
T1070.001Indicator Removal: Clear Windows Event Logs
Windows event logs wiped to remove forensic evidence using wevtutil.
T1070.004Indicator Removal: File Deletion
[Play](https://attack.mitre.org/groups/G1040) has used tools including [Wevtutil](https://attack.mitre.org/software/S0645) to remove malicious files from compromised hosts.(Citation: Trend Micro Ransomware Spotlight Play July 2023)
T1078.002Valid Accounts: Domain Accounts
[Play](https://attack.mitre.org/groups/G1040) has used valid domain accounts for access.(Citation: Trend Micro Ransomware Spotlight Play July 2023)
T1078.003Valid Accounts: Local Accounts
[Play](https://attack.mitre.org/groups/G1040) has used valid local accounts to gain initial access.(Citation: Trend Micro Ransomware Spotlight Play July 2023)
T1484Domain or Tenant Policy Modification
T1484.001Domain or Tenant Policy Modification: Group Policy Modification
T1562.001Disable or Modify Tools
Security tools including Windows Defender and AV products disabled prior to encryption.
Credential Access
Discovery
T1016System Network Configuration Discovery
T1018Remote System Discovery
[Play](https://attack.mitre.org/groups/G1040) has used tools such as [AdFind](https://attack.mitre.org/software/S0552), [Nltest](https://attack.mitre.org/software/S0359), and [BloodHound](https://attack.mitre.org/software/S0521) to enumerate shares and hostnames on compromised networks.(Citation: Trend Micro Ransomware Spotlight Play July 2023)
T1046Network Service Discovery
Network scanning tools used to enumerate hosts, services, and potential lateral movement targets.
T1057Process Discovery
[Play](https://attack.mitre.org/groups/G1040) has used the information stealer Grixba to check for a list of security processes.(Citation: Trend Micro Ransomware Spotlight Play July 2023)
T1082System Information Discovery
[Play](https://attack.mitre.org/groups/G1040) has leveraged tools to enumerate system information.(Citation: Trend Micro Ransomware Spotlight Play July 2023)
T1083File and Directory Discovery
[Play](https://attack.mitre.org/groups/G1040) has used the Grixba information stealer to list security files and processes.(Citation: Trend Micro Ransomware Spotlight Play July 2023)
T1087.002Account Discovery: Domain Account
Active Directory enumeration to identify privileged accounts and high-value targets.
T1518Software Discovery
T1518.001Software Discovery: Security Software Discovery
Lateral Movement
Collection
Exfiltration
T1030Data Transfer Size Limits
[Play](https://attack.mitre.org/groups/G1040) has split victims' files into chunks for exfiltration.(Citation: CISA Play Ransomware Advisory December 2023)(Citation: Trend Micro Ransomware Spotlight Play July 2023)
T1048Exfiltration Over Alternative Protocol
WinSCP and Rclone used to exfiltrate data to actor-controlled infrastructure and cloud storage ahead of encryption.
Command and Control
T1105Ingress Tool Transfer
[Play](https://attack.mitre.org/groups/G1040) has used [Cobalt Strike](https://attack.mitre.org/software/S0154) to download files to compromised machines.(Citation: Trend Micro Ransomware Spotlight Play July 2023)
T1219Remote Access Software
Cobalt Strike, SystemBC, and AnyDesk used as C2 frameworks for persistent access.
Impact
T1486Data Encrypted for Impact
Play ransomware uses AES-RSA hybrid encryption. Files appended with .play extension. Targets Windows and Linux/ESXi environments. Double extortion model with data published on Play leak site. Notable for NOT including ransom note in individual encrypted files — single note left at root of C: drive.
T1489Service Stop
Database, mail, backup, and security services terminated before encryption to ensure maximum file access.
T1490Inhibit System Recovery
Shadow copies deleted and Windows recovery disabled to prevent victim restoration of files.
T1657Financial Theft
Resource Development
T1587.001Develop Capabilities: Malware
[Play](https://attack.mitre.org/groups/G1040) developed and employ [Playcrypt](https://attack.mitre.org/software/S1162) ransomware.(Citation: Trend Micro Ransomware Spotlight Play July 2023)(Citation: CISA Play Ransomware Advisory December 2023)
T1588.002Obtain Capabilities: Tool
[Play](https://attack.mitre.org/groups/G1040) has used multiple tools for discovery and defense evasion purposes on compromised hosts.(Citation: CISA Play Ransomware Advisory December 2023)
Defense Impairment
T1685Disable or Modify Tools
[Play](https://attack.mitre.org/groups/G1040) has used tools including GMER, IOBit, and PowerTool to disable antivirus software.(Citation: CISA Play Ransomware Advisory December 2023)(Citation: Trend Micro Ransomware Spotlight Play July 2023)
T1685.005Disable or Modify Tools: Clear Windows Event Logs
[Play](https://attack.mitre.org/groups/G1040) has used tools to remove log files on targeted systems.(Citation: CISA Play Ransomware Advisory December 2023)(Citation: Trend Micro Ransomware Spotlight Play July 2023)
Recent victims
showing 50 of 1,295| Date | Website / victim | Sector | Country |
|---|---|---|---|
| 2026-08-06 | Signature Serviceswww.signatureservices.net | Professional Services | |
| 2026-08-06 | GCATS Investmentswww.gcatstx.com | Financial Services | US |
| 2026-08-06 | Platinum Groupwww.platinum-grp.com | Manufacturing | US |
| 2026-08-04 | First Tekwww.first-tek.com | Technology | US |
| 2026-08-04 | Preferred Financial Groupwww.preferredfinancial.com | Financial Services | US |
| 2026-07-27 | The Butcher Brotherswww.thebutcherbrotherscorp.com | Retail & E-Commerce | US |
| 2026-08-01 | Sigma Plastics Groupwww.sigmaplasticsgroup.com | Manufacturing | US |
| 2026-08-01 | Cambridge Managementwww.cambridgemgmt.net | Professional Services | US |
| 2026-07-23 | Record Go Alquilerwww.recordrentacar.com | Hospitality | ES |
| 2026-07-23 | Restaurant Depotwww.restaurantdepot.com | Retail & E-Commerce | US |
| 2024-03-06 | The DeBrulerwww.tax-mt.com | Not Found | US |
| 2024-03-06 | Tax MTwww.tax-mt.com | Professional Services | MT |
| 2026-07-21 | Kreysler & Associateswww.kreysler.com | Professional Services | US |
| 2026-07-16 | Boston Electric and Telephonewww.betcorp.com | Technology | US |
| 2026-07-16 | Wring Groupwww.wringgroup.co.uk | Professional Services | GB |
| 2026-07-16 | AG Scholteswww.agscholtes.nl | Manufacturing | NL |
| 2026-07-16 | Andorra Lifewww.andorralife.com | Healthcare | AD |
| 2026-07-16 | Svensk Direktreklamwww.sdr.se | Professional Services | SE |
| 2026-07-07 | Preneed Funeral Programswww.preneed.net | Retail & E-Commerce | US |
| 2026-07-07 | Kevin Bao Lenguyenwww.kblaa.com | Not Found | |
| 2026-07-07 | United Infrastructurewww.unitedinfrastructure.com | Energy & Utilities | US |
| 2026-07-04 | Locati Architectswww.locatiarchitects.com | Professional Services | AU |
| 2026-07-04 | Silvestri & Associates Insurancewww.silvestriandassociates.com | Financial Services | US |
| 2026-06-30 | Western Constructionwww.wciboise.com | Manufacturing | US |
| 2026-06-27 | J&J Gamingwww.jjgaming.com | Retail & E-Commerce | US |
| 2026-06-27 | Kuhnlinewww.kuhnline.com | Agriculture and Food Production | DE |
| 2026-06-26 | Benchmark Industrial Supplywww.benchmarkinc.com | Professional Services | US |
| 2026-06-17 | Greg Crosslinwww.destinlegal.com | Professional Services | US |
| 2026-06-17 | Integrated Technologieswww.itc4u.com | Technology | |
| 2026-06-17 | eurOptimumwww.europtimum.com | Technology | DE |
| 2026-06-10 | Mundt and Associateswww.mundtinc.com | Professional Services | US |
| 2026-06-10 | Rainbow Distributors USAwww.rainbowdistributorsusa.com | Retail & E-Commerce | US |
| 2026-05-12 | Pearson Fordwww.pearsonford.com | Transportation | GB |
| 2026-06-04 | Urschel Laboratorieswww.urschel.com | Agriculture and Food Production | US |
| 2026-06-02 | Dallis Law Firmwww.dallislawfirm.com | Professional Services | US |
| 2026-05-29 | The Chapelwww.thechapel.com | Other | US |
| 2026-05-29 | Corley MFGwww.corleymfg.com | Manufacturing | US |
| 2026-05-11 | Digitall Graphicswww.digitallgraphics.ca | Technology | CA |
| 2026-05-20 | Hightower Communicationswww.hightowernc.com | Technology | US |
| 2026-05-20 | GW Mechanicalwww.gwmechanical.com | Professional Services | US |
| 2026-04-21 | NL Fisherwww.nlfisher.com | Agriculture and Food Production | NL |
| 2026-05-19 | Round Hill Country Clubwww.rhcountryclub.com | Hospitality | US |
| 2026-05-15 | Legend Networking & Telecomwww.legendnt.com | Technology | US |
| 2026-05-17 | MyPillowwww.mypillow.com | Retail & E-Commerce | US |
| 2026-05-01 | De Waard Transportwww.dewaardtransport.nl | Transportation | NL |
| 2026-05-05 | Zuther Hautmannwww.z-h.de | Manufacturing | DE |
| 2026-04-20 | Infoworld Membership Systemswww.imsmars.com | Technology | |
| 2026-05-04 | Town Car Internationalwww.towncarinternational.com | Transportation | US |
| 2026-04-28 | Northern Mechanical Contractorswww.northernmc.com | Manufacturing | CA |
| 2024-03-06 | ACC Constructionwww.acc-construction.com | Manufacturing | US |

