Skip to content

Play

Ransomware Group1 claimLast activity:
Also known as:
  • Playcrypt · Alias

Overview

Play, also known as Playcrypt, is a financially motivated ransomware group first observed in June 2022. A joint FBI, CISA and Australian Cyber Security Centre advisory said Play affected businesses and critical infrastructure across North America, South America and Europe and was among the most active ransomware groups in 2024. The FBI was aware of about 900 entities allegedly exploited by Play actors as of May 2025.

Play describes itself as a closed group rather than an open ransomware-as-a-service operation. The identities, location and leadership of its core operators remain publicly unconfirmed. The name continued to appear in victim claims in 2026, including an August listing involving Woodhaven Association; leak-site listings remain actor allegations unless corroborated.

Activity and targeting

Government investigations document broad, opportunistic activity rather than an exclusive sector or regional focus. Play has affected businesses and critical infrastructure, and early Trend Micro research documented cases involving government, information technology, transportation, construction, telecommunications, health care and media organizations. Those observations came from bounded telemetry and leak-site research and should not be treated as a complete victim census.

Methods and operational characteristics

Play actors have obtained access through compromised credentials, internet-facing Remote Desktop Protocol and virtual private network services, and exploitation of public-facing applications. Documented targets have included FortiOS and Microsoft Exchange vulnerabilities. The 2025 joint advisory also described exploitation of SimpleHelp vulnerabilities by multiple ransomware groups and initial-access brokers with ties to Play, illustrating that access may involve outside providers even when the core operation remains closed.

Observed post-compromise activity includes Active Directory discovery with AdFind, BloodHound and the custom Grixba tool; credential theft with Mimikatz; defense impairment with GMER, IOBit, PowerTool and PowerShell; and lateral movement or command and control through PsExec, Cobalt Strike and SystemBC. Actors have compressed data with WinRAR and transferred it with WinSCP before deploying ransomware.

The Windows encryptor uses intermittent AES-RSA encryption, appends the .PLAY extension and is recompiled for individual attacks. Government reporting also documents an ESXi variant that powers off virtual machines and encrypts virtual-machine files. Play uses double extortion: victims are directed to email the group, may receive phone calls pressing for payment and face threatened publication of stolen data on a Tor leak site.

What type of group is it?

Play is best classified as a financially motivated ransomware group operating a closed extortion program. Public evidence does not establish a conventional open affiliate marketplace, although access brokers and outside actors may participate in individual intrusions.

A 2024 Unit 42 investigation assessed with moderate confidence that the North Korean-linked Jumpy Pisces cluster collaborated with Play in one incident, possibly as an initial-access broker or affiliate. That case does not establish that Jumpy Pisces is part of Play’s core group, that the relationship continued, or that Play is a North Korean state operation.

Incident claim

Woodhaven Lakes ransomware incident

View public claim
Incident date: Source: ransomware.livePublished: Discovered:

Claim details

Play listed Woodhaven Association and woodhavenassociation.com on August 17 and claimed it stole internal data. The listing threatened to publish a full leak unless an organization representative contacted the group. Woodhaven Lakes had already confirmed ransomware and file encryption, but it has not confirmed Play attribution, data theft, possession of authentic files, a leak, direct contact, a ransom amount or payment activity.

Impacted organizations

Impacted location

Sources