Skip to content

PLAY

Play ransomware, also known as PlayCrypt, is a ransomware operation active since June 2022 and tracked by Symantec as Balloonfly.

Profile source: Mallory opens in a new tab

PLAY

Family profile

Play ransomware, also known as PlayCrypt, is a ransomware operation active since June 2022 and tracked by Symantec as Balloonfly. It conducts double-extortion attacks, stealing victim data before encrypting systems and threatening public disclosure when ransom demands are not met. Play has targeted organizations internationally, including government, hospitality, professional services, manufacturing, construction, and healthcare-related entities; its early activity notably affected Latin American organizations before expanding more broadly. Observed intrusions have involved exploitation of Microsoft Exchange vulnerabilities, use of valid VPN credentials, and deployment through remote administration and lateral-movement tooling. Play operators have used custom tooling for enterprise reconnaissance, including enumeration of users, computers, installed software, services, security products, backup products, and remote-access tools. They have also cleared local and remote event logs, accessed files from Volume Shadow Copy Service snapshots, targeted or destroyed backups, and used RDP, SMB, and PsExec for movement within victim environments. The Windows ransomware encryptor uses hybrid RSA-AES cryptography, traverses local and network storage, and employs obfuscation, encoded strings, API hashing, and control-flow manipulation to impede analysis. It appends a Play-specific extension to affected files and uses email-based ransom negotiation. Play has been linked to ransomware-as-a-service and affiliate activity, but public reporting does not establish that every intrusion attributed to the brand was conducted by the same operators.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Lateral Movement
  • Privilege Escalation
  • Reconnaissance

Operational record

1
YARA rules
3
Ransom notes
4
Leak sites
0 available

Credential Theft

  • HandleKatz
  • Mimikatz
  • Nanodump

Defense Evasion

  • EDRKill (echo_driver.sys + DBUtil 2.3)
  • GMER
  • IOBit
  • PowerTool
  • icardagt.exe (version.dll DLL sideload)

Discovery Enum

  • AdFind
  • WKTools

Exfiltration

  • WinSCP

LOLBAS

  • PsExec

Networking

  • FRP
  • Plink

Offsec

  • Cobalt Strike
  • WinPEAS

Recent claims

Reported operators

Threat actors

10 named in public reporting
Play

Play ransomware (also known as PlayCrypt), which is developed by a group Symantec tracks as Balloonfly, was launched in June 2022...

ShadowSyndicate

It has demonstrated the use of multiple top tier Ransomware-as-a-Service (RaaS) brands such as AlphaV/Blackcat, Lockbit, Play, Royal, Cl0p, Cactus and Ransomhub.

Andariel

It has demonstrated the use of multiple top tier Ransomware-as-a-Service (RaaS) brands such as AlphaV/Blackcat, Lockbit, Play, Royal, Cl0p, Cactus and Ransomhub.

Scattered Spider

These RaaS programs include: Akira (Howling Scorpius) ALPHV (Ambitious Scorpius) DragonForce (Slippery Scorpius) Play (Fiddling Scorpius) Qilin (Spikey Scorpius) RansomHub (Spoiled Scorpius)

Fiddling Scorpius

These RaaS programs include: Akira (Howling Scorpius) ALPHV (Ambitious Scorpius) DragonForce (Slippery Scorpius) Play (Fiddling Scorpius) Qilin (Spikey Scorpius) RansomHub (Spoiled Scorpius)

Lazarus

MyPillow, the US-based bedding brand founded by election conspiracy theorist Mike Lindell, has been listed by Play ransomware extortionists as an alleged victim.

Prolific Puma

Play (AKA PlayCrypt) ransomware is a private ransomware operation that has been active since, at least, June 2022. The group operates in a double extortion method, where the victim data is stolen and leaked via a data leak site if the ransom demand is not paid.

QuadSwitcher

Play (AKA PlayCrypt) ransomware is a private ransomware operation that has been active since, at least, June 2022. The group operates in a double extortion method, where the victim data is stolen and leaked via a data leak site if the ransom demand is not paid.

RansomEXX

Symantec said it had found evidence of Balloonfly, the operator of Play ransomware, also exploiting CVE-2025-29824 against a US-based organization before Microsoft patched it.

Contagious Interview

North Korea has long been involved in ransomware attacks and has been previously associated with the Maui and Play ransomware families.

Exploited software

Vulnerabilities linked to PLAY

10 CVEs

MITRE ATT&CK

PLAY in ATT&CK

58 distinct techniques

Techniques

58 techniques
T1486 Data Encrypted for Impact T1074 Data Staged T1567 Exfiltration Over Web Service T1078 Valid Accounts T1021 Remote Services T1021.002 SMB/Windows Admin Shares T1021.001 Remote Desktop Protocol T1485 Data Destruction T1055 Process Injection T1036 Masquerading T1562 Impair Defenses T1083 File and Directory Discovery T1059.001 PowerShell T1529 System Shutdown/Reboot T1068 Exploitation for Privilege Escalation T1041 Exfiltration Over C2 Channel T1657 Financial Theft T1497.001 System Checks T1490 Inhibit System Recovery T1562.001 Disable or Modify Tools T1078.002 Valid Accounts: Domain Accounts T1078.003 Valid Accounts: Local Accounts T1133 External Remote Services T1190 Exploit Public-Facing Application T1053.005 Scheduled Task/Job: Scheduled Task T1059 Command and Scripting Interpreter T1059.003 Command and Scripting Interpreter: Windows Command Shell T1027 Obfuscated Files or Information T1070 Indicator Removal T1070.001 Indicator Removal: Clear Windows Event Logs T1484 Domain or Tenant Policy Modification T1484.001 Domain or Tenant Policy Modification: Group Policy Modification T1027.010 Obfuscated Files or Information: Command Obfuscation T1070.004 Indicator Removal: File Deletion T1003 OS Credential Dumping T1003.001 OS Credential Dumping: LSASS Memory T1003.003 OS Credential Dumping: NTDS T1552 Unsecured Credentials T1016 System Network Configuration Discovery T1018 Remote System Discovery T1046 Network Service Discovery T1057 Process Discovery T1082 System Information Discovery T1087.002 Account Discovery: Domain Account T1518 Software Discovery T1518.001 Software Discovery: Security Software Discovery T1570 Lateral Tool Transfer T1560 Archive Collected Data T1560.001 Archive Collected Data: Archive via Utility T1030 Data Transfer Size Limits T1048 Exfiltration Over Alternative Protocol T1105 Ingress Tool Transfer T1219 Remote Access Software T1489 Service Stop T1587.001 Develop Capabilities: Malware T1588.002 Obtain Capabilities: Tool T1685 Disable or Modify Tools T1685.005 Disable or Modify Tools: Clear Windows Event Logs

Reporting

Research mentioning PLAY

Aug 12
Hookphish

Ransomware Group clop Hits: HONGHE-TECH.COM

The Clop ransomware operation has repeatedly targeted enterprise networks with intrusions that begin with phishing or exploitation of exposed systems, followed by manual lateral movement, credential theft, and domain-wide deployment. Reporting from ANSSI and AhnLab linked earlier campaigns to TA505, describing attacks in which operators used tools such as Cobalt Strike and Mimikatz, encrypted files with .Clop or .CIop extensions, and disrupted business operations at victims including E-Land Group, Software AG, and reportedly Indiabulls Group. Analysts also observed Clop using signed malware components, targeting Active Directory environments, stopping business-critical services before encryption, and in some cases preserving shadow copies depending on the variant. The group increasingly shifted from encryption-only attacks to double extortion and broader data-leak pressure tactics. Clop operators published stolen files on leak sites, demanded multimillion-dollar payments, contacted victims' customers directly to intensify pressure, and were tied to mass data-theft campaigns exploiting managed file transfer flaws such as CVE-2023-0669 in Fortra GoAnywhere MFT, which was linked to theft from about 130 companies. More recent victim listings attributed to Clop include organizations in the U.S., Canada, Peru, China, Taiwan, and Europe across technology, manufacturing, retail, and other sectors, underscoring the group's continued global focus on enterprise-scale ransomware and data-breach operations.

Aug 12
Hookphish

Ransomware Group clop Hits: 9ALTITUDES.COM

Aug 12
Hookphish

Ransomware Group clop Hits: WATERLANDPE.COM

Aug 12
Hookphish

Ransomware Group clop Hits: NETPOWER.COM

Aug 12
Hookphish

Ransomware Group clop Hits: ALDOGROUP.COM (ALDOSHOES.COM)

Aug 12
Hookphish

Ransomware Group clop Hits: IRCO.COM

Aug 12
Hookphish

Ransomware Group clop Hits: LARGAN.COM.TW

Jul 27
Hookphish

Ransomware Group incransom Hits: takethehop.com

The ransomware group INC Ransom has been linked to an attack on takethehop.com, the website of The HOP, a regional public transit system operated by the Hill Country Transit District in Texas. The incident was reported as a data breach and ransomware event, adding a public-sector transportation victim to the group’s growing list of targets as double-extortion campaigns continue to hit North American organizations. MITRE ATT&CK describes INC Ransom as an intrusion set that commonly gains access through phishing, compromised valid accounts, and exploitation of public-facing applications including CVE-2023-3519 in Citrix NetScaler, then conducts discovery, lateral movement, data staging, exfiltration, and encryption. The group has been observed using tools such as AnyDesk, PuTTY, PsExec, MegaSync, Advanced IP Scanner, WMIC, 7-Zip, and WinRAR, while disguising activity and disabling defenses before deploying ransomware. A recent Cyble global threat report also identified INC Ransom among the major ransomware actors active in 2026, underscoring the continued scale of double-extortion operations worldwide.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.