G1040 · 26 ATT&CK techniques · 6 correlated reports

Play

Aliases: None listed

Play is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a double-extortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.

Open interactive actor investigation

ATT&CK techniques

Correlated CTI and IR reports

Continue the investigation