HackerFeeds
All ransomware groups

play

1,268 tracked victims
·first seen 2022-11-26·last activity 2026-06-17

Group profile

Initially observed in June 2022, the Play ransomware (a.k.a PlayCrypt) operates through double extortion, targeting numerous organizations in Latin America. Its Initial Access method is quite similar to other ransomwares, involving attacks such as Phishing, Exposed Services to the Internet, and Valid Account compromises.<br> <br> On April 19, 2023, the security company Symantec published two new tools developed by the Play group. These tools allow the malicious actor to enumerate and exfiltrate data from the internal network. The post mentions the following: 'Play threat actors use the .NET infostealer to enumerate software and services via WMI, WinRM, Remote Registry, and Remote Service. The malware checks for the existence of security and backup software, as well as remote administration tools and other programs, saving the information in .CSV files that are compressed into a .ZIP file for later manual exfiltration by threat actors.'Source: https://github.com/crocodyli/ThreatActors-TTPs

MITRE ATT&CK TTPs

TA0001

Initial Access

  • T1078Valid Accounts

    Compromised VPN credentials used to authenticate directly to victim networks.

  • T1190Exploit Public-Facing Application

    Play exploits vulnerabilities in Microsoft Exchange (ProxyNotShell CVE-2022-41040/CVE-2022-41082), FortiOS SSL VPN (CVE-2018-13379), and RDP to gain initial access.

TA0002

Execution

  • T1053.005Scheduled Task/Job: Scheduled Task

    Scheduled tasks used for payload persistence and execution across compromised hosts.

  • T1059Command and Scripting Interpreter

  • T1059.001Command and Scripting Interpreter: PowerShell

    PowerShell scripts used for payload execution and post-exploitation tooling deployment.

TA0005

Defense Evasion

  • T1027Obfuscated Files or Information

    Play ransomware payloads are split into multiple parts to bypass AV scanning; parts reassembled on target systems.

  • T1070Indicator Removal

  • T1070.001Indicator Removal: Clear Windows Event Logs

    Windows event logs wiped to remove forensic evidence using wevtutil.

  • T1484Domain or Tenant Policy Modification

  • T1484.001Domain or Tenant Policy Modification: Group Policy Modification

  • T1562.001Disable or Modify Tools

    Security tools including Windows Defender and AV products disabled prior to encryption.

TA0006

Credential Access

  • T1003OS Credential Dumping

  • T1003.001OS Credential Dumping: LSASS Memory

    Mimikatz and similar tools used for LSASS memory dumping to harvest credentials.

  • T1003.003OS Credential Dumping: NTDS

    NTDS.dit extracted from domain controllers to obtain all domain account hashes.

  • T1552Unsecured Credentials

TA0007

Discovery

  • T1016System Network Configuration Discovery

  • T1046Network Service Discovery

    Network scanning tools used to enumerate hosts, services, and potential lateral movement targets.

  • T1087.002Account Discovery: Domain Account

    Active Directory enumeration to identify privileged accounts and high-value targets.

  • T1518Software Discovery

  • T1518.001Software Discovery: Security Software Discovery

TA0008

Lateral Movement

  • T1021.001Remote Services: Remote Desktop Protocol

    RDP used for lateral movement across victim networks.

  • T1021.002Remote Services: SMB/Windows Admin Shares

    PsExec and SMB used to propagate payloads laterally.

  • T1570Lateral Tool Transfer

TA0009

Collection

  • T1560Archive Collected Data

  • T1560.001Archive Collected Data: Archive via Utility

    WinRAR used to compress and archive stolen data prior to exfiltration.

TA0010

Exfiltration

  • T1048Exfiltration Over Alternative Protocol

    WinSCP and Rclone used to exfiltrate data to actor-controlled infrastructure and cloud storage ahead of encryption.

TA0011

Command and Control

  • T1219Remote Access Software

    Cobalt Strike, SystemBC, and AnyDesk used as C2 frameworks for persistent access.

TA0040

Impact

  • T1486Data Encrypted for Impact

    Play ransomware uses AES-RSA hybrid encryption. Files appended with .play extension. Targets Windows and Linux/ESXi environments. Double extortion model with data published on Play leak site. Notable for NOT including ransom note in individual encrypted files — single note left at root of C: drive.

  • T1489Service Stop

    Database, mail, backup, and security services terminated before encryption to ensure maximum file access.

  • T1490Inhibit System Recovery

    Shadow copies deleted and Windows recovery disabled to prevent victim restoration of files.

  • T1657Financial Theft

Recent victims

showing 50 of 1,268
DateWebsite / victimSectorCountry
2026-06-17Not FoundUS
2026-06-17
itc4u.com
Integrated Technologieswww.itc4u.com
Technology
2026-06-17TechnologyDE
2026-06-10
mundtinc.com
Mundt and Associateswww.mundtinc.com
Business ServicesUS
2026-06-10
rainbowdistributorsusa.com
Rainbow Distributors USAwww.rainbowdistributorsusa.com
Consumer ServicesUS
2026-05-12Transportation/LogisticsGB
2026-06-04
urschel.com
Urschel Laboratorieswww.urschel.com
Agriculture and Food ProductionUS
2026-06-02
dallislawfirm.com
Dallis Law Firmwww.dallislawfirm.com
Business ServicesUS
2026-05-29Not FoundUS
2026-05-29ManufacturingUS
2026-05-11
digitallgraphics.ca
Digitall Graphicswww.digitallgraphics.ca
TechnologyCA
2026-05-20
hightowernc.com
Hightower Communicationswww.hightowernc.com
TelecommunicationUS
2026-05-20Business ServicesUS
2026-04-21Agriculture and Food ProductionNL
2026-05-19
rhcountryclub.com
Round Hill Country Clubwww.rhcountryclub.com
Hospitality and TourismUS
2026-05-15
legendnt.com
Legend Networking & Telecomwww.legendnt.com
TelecommunicationUS
2026-05-17Consumer ServicesUS
2026-05-01
dewaardtransport.nl
De Waard Transportwww.dewaardtransport.nl
Transportation/LogisticsNL
2026-05-05
z-h.de
Zuther Hautmannwww.z-h.de
Not FoundDE
2026-04-20
imsmars.com
Infoworld Membership Systemswww.imsmars.com
Technology
2026-05-04
towncarinternational.com
Town Car Internationalwww.towncarinternational.com
Transportation/LogisticsUS
2026-04-28
northernmc.com
Northern Mechanical Contractorswww.northernmc.com
ConstructionCA
2024-03-06ConstructionUS
2026-05-01
goiwc.com
IWC Food Servicewww.goiwc.com
Agriculture and Food ProductionUS
2026-05-09
ashcrofthomes.ca
Ashcroft Homeswww.ashcrofthomes.ca
ConstructionCA
2024-03-06ManufacturingUS
2026-04-28
kedistributing.com
K & E Distributingwww.kedistributing.com
Transportation/LogisticsUS
2026-04-30
aolaml.com
Accessoires Outillage Lteewww.aolaml.com
ManufacturingCA
2026-05-02
emaengineer.com
EMA Engineering & Consultingwww.emaengineer.com
Business ServicesUS
2026-04-06Not FoundUS
2026-04-06TechnologyUS
2026-02-04
barnessolicitors.co.uk
Barnes Solicitors LLPwww.barnessolicitors.co.uk
Business ServicesGB
2026-03-05Consumer ServicesUS
2026-03-24ManufacturingSE
2024-03-06
colorado-group.com
Colorado Constructionwww.colorado-group.com
ConstructionUS
2024-03-06Consumer ServicesDE
2026-03-24
wkclaw.net
Weber Kracht & Chellewwww.wkclaw.net
Business ServicesUS
2026-03-23ManufacturingGB
2025-03-16ConstructionGB
2026-03-30Transportation/LogisticsUS
2026-01-12
ampex.com
Ampex Data Systemswww.ampex.com
TechnologyUS
2026-03-20
valleyplatinginc.com
Valley Plating Incwww.valleyplatinginc.com
ManufacturingUS
2026-03-21ManufacturingGB
2026-03-18
teamtpis.com
TPIS Industrial Serviceswww.teamtpis.com
ManufacturingUS
2026-03-19
aretsifl.com
All Real Estate Title Solutionswww.aretsifl.com
Business ServicesUS
2026-03-24
roxiticus.com
Roxiticus Golf Clubwww.roxiticus.com
Hospitality and TourismUS
2026-03-16Not FoundUS
2026-03-13
ascentasset.com
Ascent Asset Groupwww.ascentasset.com
Financial ServicesUS
2024-03-06
capital-drug.com
Capital Wholesale Drugwww.capital-drug.com
HealthcareUS
2026-03-24
blockeng.com
Block Engineeringwww.blockeng.com
TechnologyUS