NEW: Group Profiler — instant APT intel lookup. Try it →

Play

Overview

Play is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a double-extortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.

Naming & attribution

Play is tracked under 1 names across the industry. It uses 26 documented ATT&CK techniques — more than 60% of the 174 groups tracked here. Activity attributed since at least 2022.

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1048 Exfiltration Over Alternative Protocol — used by 2 of 174 groups

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • Aquatic Panda China — 14 shared techniques (30% overlap)
  • FIN8 — 14 shared techniques (29% overlap)
  • MirrorFace China — 15 shared techniques (28% overlap)
  • Medusa Group — 17 shared techniques (26% overlap)
  • Ke3chang China — 15 shared techniques (26% overlap)
  • Cinnamon Tempest China — 9 shared techniques (25% overlap)

Capabilities

  • Exploitation of public-facing / client applications — ATT&CK T1190

TTPs — 26 techniques across 13 tactics

Resource Development

Initial Access

Execution

Persistence

Stealth

Defense Impairment

Credential Access

Lateral Movement

Collection

Command and Control

Impact

Tools & malware (9)

Nltest · AdFind · PsExec · Empire · Wevtutil · Cobalt Strike · Playcrypt · BloodHound · Mimikatz

Reporting (2)