Credential Theft
- HandleKatz
- Mimikatz
- Nanodump
Play, also known as PlayCrypt, is a ransomware operation first observed in mid-2022 that conducts double-extortion attacks against organizations worldwide.
Profile source: Mallory opens in a new tabPLAY
Play, also known as PlayCrypt, is a ransomware operation first observed in mid-2022 that conducts double-extortion attacks against organizations worldwide. It is known for stealing data prior to encryption and threatening public release to pressure victims, and it has remained an active, high-volume threat across sectors including healthcare, government, finance, construction, manufacturing, telecommunications, education, and other critical infrastructure and enterprise environments. Public reporting has associated the operation with hundreds of victims by 2025, and victim disclosures continued through 2026.
Play primarily targets Windows environments and has also developed Linux-focused encryptors, including an ESXi/Linux variant assessed as the first known Linux version of the family. Research has linked that Linux/ESXi branch to code overlap with the leaked Babuk ESXi source, reflecting broader ransomware reuse in hypervisor-targeting malware. Play has also been observed using intermittent encryption to accelerate impact and reduce detection opportunities, and it can inhibit recovery by deleting shadow copies.
The operation’s tradecraft is consistent with mature post-compromise ransomware activity. Reported behaviors include exploitation of public-facing applications, abuse of valid accounts, PowerShell execution, credential dumping, network and security-tool discovery, lateral movement over remote services such as RDP and SMB, tool transfer within victim networks, log clearing, disabling or modifying security controls, and data archiving and exfiltration before encryption. Reporting also notes use of vulnerable drivers to terminate endpoint security products in some intrusions, as well as exploitation of Windows CLFS elevation-of-privilege vulnerabilities in broader ransomware ecosystem activity associated with Play.
Play is commonly discussed as a ransomware group rather than a purely technical malware family, and it has been linked in reporting to ransomware-as-a-service ecosystem activity and to infrastructure provided by bulletproof hosting operators. Some reporting has also described North Korean state-linked actors using Play ransomware in certain intrusions, though this does not establish that the core Play operators themselves are North Korean. The operation is notable for rapid deployment in some incidents, suggesting disciplined hands-on-keyboard intrusion workflows and efficient monetization through extortion.
Reported operators
These RaaS programs include: Akira (Howling Scorpius) ALPHV (Ambitious Scorpius) DragonForce (Slippery Scorpius) Play (Fiddling Scorpius) Qilin (Spikey Scorpius) RansomHub (Spoiled Scorpius)
These RaaS programs include: Akira (Howling Scorpius) ALPHV (Ambitious Scorpius) DragonForce (Slippery Scorpius) Play (Fiddling Scorpius) Qilin (Spikey Scorpius) RansomHub (Spoiled Scorpius)
MyPillow, the US-based bedding brand founded by election conspiracy theorist Mike Lindell, has been listed by Play ransomware extortionists as an alleged victim.
"...Super Quik had multiple internal files and surveillance video footage exposed by the Play ransomware operation, which claimed to have exfiltrated a 5.5 GB dataset from its systems."
Play (AKA PlayCrypt) ransomware is a private ransomware operation that has been active since, at least, June 2022. The group operates in a double extortion method, where the victim data is stolen and leaked via a data leak site if the ransom demand is not paid.
Play (AKA PlayCrypt) ransomware is a private ransomware operation that has been active since, at least, June 2022. The group operates in a double extortion method, where the victim data is stolen and leaked via a data leak site if the ransom demand is not paid.
Play (AKA PlayCrypt) ransomware is a private ransomware operation that has been active since, at least, June 2022. The group operates in a double extortion method, where the victim data is stolen and leaked via a data leak site if the ransom demand is not paid.
Symantec said it had found evidence of Balloonfly, the operator of Play ransomware, also exploiting CVE-2025-29824 against a US-based organization before Microsoft patched it.
North Korea has long been involved in ransomware attacks and has been previously associated with the Maui and Play ransomware families.
Exploited software
MITRE ATT&CK
Reporting
The ransomware group INC Ransom has been linked to an attack on takethehop.com, the website of The HOP, a regional public transit system operated by the Hill Country Transit District in Texas. The incident was reported as a data breach and ransomware event, adding a public-sector transportation victim to the group’s growing list of targets as double-extortion campaigns continue to hit North American organizations. MITRE ATT&CK describes INC Ransom as an intrusion set that commonly gains access through phishing, compromised valid accounts, and exploitation of public-facing applications including CVE-2023-3519 in Citrix NetScaler, then conducts discovery, lateral movement, data staging, exfiltration, and encryption. The group has been observed using tools such as AnyDesk, PuTTY, PsExec, MegaSync, Advanced IP Scanner, WMIC, 7-Zip, and WinRAR, while disguising activity and disabling defenses before deploying ransomware. A recent Cyble global threat report also identified INC Ransom among the major ransomware actors active in 2026, underscoring the continued scale of double-extortion operations worldwide.
SonicWall has patched two vulnerabilities that are being actively exploited against SMA 1000 Series appliances, affecting models including 6210, 7210, and 8200v. The flaws, tracked as CVE-2026-15409 and CVE-2026-15410, impact multiple 12.4.3 and 12.5.0 platform-hotfix releases. SonicWall described CVE-2026-15409 as a critical unauthenticated SSRF issue in the Appliance Work Place interface and CVE-2026-15410 as a high-severity code injection flaw in the Appliance Management Console that can allow an authenticated administrator to execute arbitrary operating system commands. SonicWall said the vulnerabilities have been exploited together in the wild and released hotfixes to address them. Government and vendor advisories urged organizations to update immediately and investigate appliances for signs of compromise, warning that patching alone may not be sufficient if an appliance has already been breached. SonicWall recommended reviewing logs, re-imaging or re-deploying affected systems where indicators are found, changing user and administrator passwords, and resetting TOTP tokens. The Canadian Centre for Cyber Security highlighted the advisory, and CISA added both vulnerabilities to its Known Exploited Vulnerabilities catalog the same day, underscoring the urgency for defenders to remediate exposed SMA1000 deployments.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.