Credential Theft
- HandleKatz
- Mimikatz
- Nanodump
Play ransomware, also known as PlayCrypt, is a ransomware operation active since June 2022 and tracked by Symantec as Balloonfly.
Profile source: Mallory opens in a new tabPLAY
Play ransomware, also known as PlayCrypt, is a ransomware operation active since June 2022 and tracked by Symantec as Balloonfly. It conducts double-extortion attacks, stealing victim data before encrypting systems and threatening public disclosure when ransom demands are not met. Play has targeted organizations internationally, including government, hospitality, professional services, manufacturing, construction, and healthcare-related entities; its early activity notably affected Latin American organizations before expanding more broadly. Observed intrusions have involved exploitation of Microsoft Exchange vulnerabilities, use of valid VPN credentials, and deployment through remote administration and lateral-movement tooling. Play operators have used custom tooling for enterprise reconnaissance, including enumeration of users, computers, installed software, services, security products, backup products, and remote-access tools. They have also cleared local and remote event logs, accessed files from Volume Shadow Copy Service snapshots, targeted or destroyed backups, and used RDP, SMB, and PsExec for movement within victim environments. The Windows ransomware encryptor uses hybrid RSA-AES cryptography, traverses local and network storage, and employs obfuscation, encoded strings, API hashing, and control-flow manipulation to impede analysis. It appends a Play-specific extension to affected files and uses email-based ransom negotiation. Play has been linked to ransomware-as-a-service and affiliate activity, but public reporting does not establish that every intrusion attributed to the brand was conducted by the same operators.
Reported operators
Play ransomware (also known as PlayCrypt), which is developed by a group Symantec tracks as Balloonfly, was launched in June 2022...
It has demonstrated the use of multiple top tier Ransomware-as-a-Service (RaaS) brands such as AlphaV/Blackcat, Lockbit, Play, Royal, Cl0p, Cactus and Ransomhub.
It has demonstrated the use of multiple top tier Ransomware-as-a-Service (RaaS) brands such as AlphaV/Blackcat, Lockbit, Play, Royal, Cl0p, Cactus and Ransomhub.
These RaaS programs include: Akira (Howling Scorpius) ALPHV (Ambitious Scorpius) DragonForce (Slippery Scorpius) Play (Fiddling Scorpius) Qilin (Spikey Scorpius) RansomHub (Spoiled Scorpius)
These RaaS programs include: Akira (Howling Scorpius) ALPHV (Ambitious Scorpius) DragonForce (Slippery Scorpius) Play (Fiddling Scorpius) Qilin (Spikey Scorpius) RansomHub (Spoiled Scorpius)
MyPillow, the US-based bedding brand founded by election conspiracy theorist Mike Lindell, has been listed by Play ransomware extortionists as an alleged victim.
Play (AKA PlayCrypt) ransomware is a private ransomware operation that has been active since, at least, June 2022. The group operates in a double extortion method, where the victim data is stolen and leaked via a data leak site if the ransom demand is not paid.
Play (AKA PlayCrypt) ransomware is a private ransomware operation that has been active since, at least, June 2022. The group operates in a double extortion method, where the victim data is stolen and leaked via a data leak site if the ransom demand is not paid.
Symantec said it had found evidence of Balloonfly, the operator of Play ransomware, also exploiting CVE-2025-29824 against a US-based organization before Microsoft patched it.
North Korea has long been involved in ransomware attacks and has been previously associated with the Maui and Play ransomware families.
Exploited software
MITRE ATT&CK
Reporting
The Clop ransomware operation has repeatedly targeted enterprise networks with intrusions that begin with phishing or exploitation of exposed systems, followed by manual lateral movement, credential theft, and domain-wide deployment. Reporting from ANSSI and AhnLab linked earlier campaigns to TA505, describing attacks in which operators used tools such as Cobalt Strike and Mimikatz, encrypted files with .Clop or .CIop extensions, and disrupted business operations at victims including E-Land Group, Software AG, and reportedly Indiabulls Group. Analysts also observed Clop using signed malware components, targeting Active Directory environments, stopping business-critical services before encryption, and in some cases preserving shadow copies depending on the variant. The group increasingly shifted from encryption-only attacks to double extortion and broader data-leak pressure tactics. Clop operators published stolen files on leak sites, demanded multimillion-dollar payments, contacted victims' customers directly to intensify pressure, and were tied to mass data-theft campaigns exploiting managed file transfer flaws such as CVE-2023-0669 in Fortra GoAnywhere MFT, which was linked to theft from about 130 companies. More recent victim listings attributed to Clop include organizations in the U.S., Canada, Peru, China, Taiwan, and Europe across technology, manufacturing, retail, and other sectors, underscoring the group's continued global focus on enterprise-scale ransomware and data-breach operations.
The ransomware group INC Ransom has been linked to an attack on takethehop.com, the website of The HOP, a regional public transit system operated by the Hill Country Transit District in Texas. The incident was reported as a data breach and ransomware event, adding a public-sector transportation victim to the group’s growing list of targets as double-extortion campaigns continue to hit North American organizations. MITRE ATT&CK describes INC Ransom as an intrusion set that commonly gains access through phishing, compromised valid accounts, and exploitation of public-facing applications including CVE-2023-3519 in Citrix NetScaler, then conducts discovery, lateral movement, data staging, exfiltration, and encryption. The group has been observed using tools such as AnyDesk, PuTTY, PsExec, MegaSync, Advanced IP Scanner, WMIC, 7-Zip, and WinRAR, while disguising activity and disabling defenses before deploying ransomware. A recent Cyble global threat report also identified INC Ransom among the major ransomware actors active in 2026, underscoring the continued scale of double-extortion operations worldwide.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.