Skip to content

PLAY

Play, also known as PlayCrypt, is a ransomware operation first observed in mid-2022 that conducts double-extortion attacks against organizations worldwide.

Profile source: Mallory opens in a new tab

PLAY

Family profile

Play, also known as PlayCrypt, is a ransomware operation first observed in mid-2022 that conducts double-extortion attacks against organizations worldwide. It is known for stealing data prior to encryption and threatening public release to pressure victims, and it has remained an active, high-volume threat across sectors including healthcare, government, finance, construction, manufacturing, telecommunications, education, and other critical infrastructure and enterprise environments. Public reporting has associated the operation with hundreds of victims by 2025, and victim disclosures continued through 2026.

Play primarily targets Windows environments and has also developed Linux-focused encryptors, including an ESXi/Linux variant assessed as the first known Linux version of the family. Research has linked that Linux/ESXi branch to code overlap with the leaked Babuk ESXi source, reflecting broader ransomware reuse in hypervisor-targeting malware. Play has also been observed using intermittent encryption to accelerate impact and reduce detection opportunities, and it can inhibit recovery by deleting shadow copies.

The operation’s tradecraft is consistent with mature post-compromise ransomware activity. Reported behaviors include exploitation of public-facing applications, abuse of valid accounts, PowerShell execution, credential dumping, network and security-tool discovery, lateral movement over remote services such as RDP and SMB, tool transfer within victim networks, log clearing, disabling or modifying security controls, and data archiving and exfiltration before encryption. Reporting also notes use of vulnerable drivers to terminate endpoint security products in some intrusions, as well as exploitation of Windows CLFS elevation-of-privilege vulnerabilities in broader ransomware ecosystem activity associated with Play.

Play is commonly discussed as a ransomware group rather than a purely technical malware family, and it has been linked in reporting to ransomware-as-a-service ecosystem activity and to infrastructure provided by bulletproof hosting operators. Some reporting has also described North Korean state-linked actors using Play ransomware in certain intrusions, though this does not establish that the core Play operators themselves are North Korean. The operation is notable for rapid deployment in some incidents, suggesting disciplined hands-on-keyboard intrusion workflows and efficient monetization through extortion.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Extortion
  • Lateral Movement
  • Post Exploitation
  • Privilege Escalation
  • Reconnaissance

Operational record

1
YARA rules
3
Ransom notes
3
Leak sites
0 available

Credential Theft

  • HandleKatz
  • Mimikatz
  • Nanodump

Defense Evasion

  • EDRKill (echo_driver.sys + DBUtil 2.3)
  • GMER
  • IOBit
  • PowerTool
  • icardagt.exe (version.dll DLL sideload)

Discovery Enum

  • AdFind
  • WKTools

Exfiltration

  • WinSCP

LOLBAS

  • PsExec

Networking

  • FRP
  • Plink

Offsec

  • Cobalt Strike
  • WinPEAS

Recent claims

Reported operators

Threat actors

9 named in public reporting
Scattered Spider

These RaaS programs include: Akira (Howling Scorpius) ALPHV (Ambitious Scorpius) DragonForce (Slippery Scorpius) Play (Fiddling Scorpius) Qilin (Spikey Scorpius) RansomHub (Spoiled Scorpius)

Fiddling Scorpius

These RaaS programs include: Akira (Howling Scorpius) ALPHV (Ambitious Scorpius) DragonForce (Slippery Scorpius) Play (Fiddling Scorpius) Qilin (Spikey Scorpius) RansomHub (Spoiled Scorpius)

Lazarus

MyPillow, the US-based bedding brand founded by election conspiracy theorist Mike Lindell, has been listed by Play ransomware extortionists as an alleged victim.

Play

"...Super Quik had multiple internal files and surveillance video footage exposed by the Play ransomware operation, which claimed to have exfiltrated a 5.5 GB dataset from its systems."

Prolific Puma

Play (AKA PlayCrypt) ransomware is a private ransomware operation that has been active since, at least, June 2022. The group operates in a double extortion method, where the victim data is stolen and leaked via a data leak site if the ransom demand is not paid.

Andariel

Play (AKA PlayCrypt) ransomware is a private ransomware operation that has been active since, at least, June 2022. The group operates in a double extortion method, where the victim data is stolen and leaked via a data leak site if the ransom demand is not paid.

QuadSwitcher

Play (AKA PlayCrypt) ransomware is a private ransomware operation that has been active since, at least, June 2022. The group operates in a double extortion method, where the victim data is stolen and leaked via a data leak site if the ransom demand is not paid.

RansomEXX

Symantec said it had found evidence of Balloonfly, the operator of Play ransomware, also exploiting CVE-2025-29824 against a US-based organization before Microsoft patched it.

Contagious Interview

North Korea has long been involved in ransomware attacks and has been previously associated with the Maui and Play ransomware families.

Exploited software

Vulnerabilities linked to PLAY

10 CVEs

MITRE ATT&CK

PLAY in ATT&CK

54 distinct techniques

Techniques

54 techniques
T1486 Data Encrypted for Impact T1083 File and Directory Discovery T1021 Remote Services T1059.001 PowerShell T1529 System Shutdown/Reboot T1068 Exploitation for Privilege Escalation T1567 Exfiltration Over Web Service T1041 Exfiltration Over C2 Channel T1562 Impair Defenses T1657 Financial Theft T1497.001 System Checks T1490 Inhibit System Recovery T1562.001 Disable or Modify Tools T1078 Valid Accounts T1078.002 Valid Accounts: Domain Accounts T1078.003 Valid Accounts: Local Accounts T1133 External Remote Services T1190 Exploit Public-Facing Application T1053.005 Scheduled Task/Job: Scheduled Task T1059 Command and Scripting Interpreter T1059.003 Command and Scripting Interpreter: Windows Command Shell T1027 Obfuscated Files or Information T1070 Indicator Removal T1070.001 Indicator Removal: Clear Windows Event Logs T1484 Domain or Tenant Policy Modification T1484.001 Domain or Tenant Policy Modification: Group Policy Modification T1027.010 Obfuscated Files or Information: Command Obfuscation T1070.004 Indicator Removal: File Deletion T1003 OS Credential Dumping T1003.001 OS Credential Dumping: LSASS Memory T1003.003 OS Credential Dumping: NTDS T1552 Unsecured Credentials T1016 System Network Configuration Discovery T1018 Remote System Discovery T1046 Network Service Discovery T1057 Process Discovery T1082 System Information Discovery T1087.002 Account Discovery: Domain Account T1518 Software Discovery T1518.001 Software Discovery: Security Software Discovery T1021.001 Remote Services: Remote Desktop Protocol T1021.002 Remote Services: SMB/Windows Admin Shares T1570 Lateral Tool Transfer T1560 Archive Collected Data T1560.001 Archive Collected Data: Archive via Utility T1030 Data Transfer Size Limits T1048 Exfiltration Over Alternative Protocol T1105 Ingress Tool Transfer T1219 Remote Access Software T1489 Service Stop T1587.001 Develop Capabilities: Malware T1588.002 Obtain Capabilities: Tool T1685 Disable or Modify Tools T1685.005 Disable or Modify Tools: Clear Windows Event Logs

Reporting

Research mentioning PLAY

Jul 27
Hookphish

Ransomware Group incransom Hits: takethehop.com

The ransomware group INC Ransom has been linked to an attack on takethehop.com, the website of The HOP, a regional public transit system operated by the Hill Country Transit District in Texas. The incident was reported as a data breach and ransomware event, adding a public-sector transportation victim to the group’s growing list of targets as double-extortion campaigns continue to hit North American organizations. MITRE ATT&CK describes INC Ransom as an intrusion set that commonly gains access through phishing, compromised valid accounts, and exploitation of public-facing applications including CVE-2023-3519 in Citrix NetScaler, then conducts discovery, lateral movement, data staging, exfiltration, and encryption. The group has been observed using tools such as AnyDesk, PuTTY, PsExec, MegaSync, Advanced IP Scanner, WMIC, 7-Zip, and WinRAR, while disguising activity and disabling defenses before deploying ransomware. A recent Cyble global threat report also identified INC Ransom among the major ransomware actors active in 2026, underscoring the continued scale of double-extortion operations worldwide.

Jul 27
Cyberveille

Rapport Cyble H1 2026 : 3 836 attaques ransomware et paysage cyber mondial en escalade | CyberVeille

Jul 21
Cyber Security News

SonicWall 0-day Vulnerabilities Exploited in the Wild to Deploy Custom Malware

SonicWall has patched two vulnerabilities that are being actively exploited against SMA 1000 Series appliances, affecting models including 6210, 7210, and 8200v. The flaws, tracked as CVE-2026-15409 and CVE-2026-15410, impact multiple 12.4.3 and 12.5.0 platform-hotfix releases. SonicWall described CVE-2026-15409 as a critical unauthenticated SSRF issue in the Appliance Work Place interface and CVE-2026-15410 as a high-severity code injection flaw in the Appliance Management Console that can allow an authenticated administrator to execute arbitrary operating system commands. SonicWall said the vulnerabilities have been exploited together in the wild and released hotfixes to address them. Government and vendor advisories urged organizations to update immediately and investigate appliances for signs of compromise, warning that patching alone may not be sufficient if an appliance has already been breached. SonicWall recommended reviewing logs, re-imaging or re-deploying affected systems where indicators are found, changing user and administrator passwords, and resetting TOTP tokens. The Canadian Centre for Cyber Security highlighted the advisory, and CISA added both vulnerabilities to its Known Exploited Vulnerabilities catalog the same day, underscoring the urgency for defenders to remediate exposed SMA1000 deployments.

Jul 21
Socradar

SonicWall SMA Flaws Lead to KNUCKLEBALL Malware

Jul 21
Help Net Security

SonicWall SMA zero-days were exploited weeks before disclosure - Help Net Security

Jul 20
Security Week

SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch - SecurityWeek

Jul 20
Vulert

SonicWall SMA Zero-Days Exploited

Jul 20
Security Affairs

Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appliances

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.