NEW: Group Profiler — instant APT intel lookup. Try it →

← threatfilter.dev / all groups / Play

Play

Overview

Play is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a double-extortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.

Capabilities

  • Exploitation of public-facing / client applications — ATT&CK T1190

TTPs — 26 techniques across 13 tactics

Resource Development

Initial Access

Execution

Persistence

Stealth

Defense Impairment

Credential Access

Lateral Movement

Collection

Command and Control

Impact

Tools & malware (9)

Nltest · AdFind · PsExec · Empire · Wevtutil · Cobalt Strike · Playcrypt · BloodHound · Mimikatz

Reporting (2)