Skip to content

— Play

Threat-actor battle card · maintained from public sources · last updated 2026-09-06 · also known as PlayCrypt

CategoryRansomware
AttributionUnknown (financially motivated; no state nexus identified)
First seenJune 2022
StatusActive
Victims YTD1200+
Primary targetsManufacturing, Construction/Engineering, Retail/Hospitality, Technology, Professional Services, SMBs

Overview

Play (also known as PlayCrypt) is a financially motivated ransomware group active since June 2022. The FBI and CISA documented approximately 900 confirmed victims by May 2025, spanning North America, South America, and Europe. The group has consistently ranked in the global top-10 and directs roughly 85% of its attacks against US organisations. It operates a double-extortion model — exfiltrating data before encrypting, then threatening publication on a Tor-hosted leak site — but with an unusual ransom-note design: no demand or payment details are included; victims are instructed to contact the group via email only. No RaaS affiliate programme has been confirmed; Play appears to operate as a closed crew. A joint CISA/FBI/ASD ACSC advisory (AA23-352A) was issued December 2023 and updated June 2025.

Tradecraft

  • Initial access: Exploits VPN appliance vulnerabilities — primarily FortiOS and Ivanti Connect Secure flaws — as well as valid credentials and exposed RDP. Optimised for speed against SMBs (<250 employees), achieving full domain compromise in hours.
  • Recon: Grixba (custom Play-built info-stealer) to enumerate network and credential data; AdFind for Active Directory queries; BloodHound for AD attack-path mapping. Group identifies misconfigured GPOs, weak service accounts, and Kerberoastable accounts rapidly.
  • Defence evasion: GMER, IOBit, PowerTool to delete logs and disable security products; PowerShell to disable Microsoft Defender. Each ransomware binary is recompiled per attack with a unique hash to bypass signature-based detection.
  • Lateral movement: PsExec for remote execution across the network.
  • Credential access: Mimikatz for domain administrator credential theft.
  • Encryption: Appends .PLAY extension; Windows and ESXi/VMware variants both operational.
  • Extortion channel: Victims receive ransom note with an @gmx.de or @web.de email contact only. On deadline expiry, data is published to the group's Tor-hosted DLS.

Notable recent victims

  • Western Construction (US, construction) — DLS June 30, 2026; 🟥 unverified
  • Kuhnline (DE, construction) — DLS June 27, 2026; data scope unconfirmed; 🟥 unverified
  • MyPillow (US, manufacturing/retail) — DLS June 2026
  • Pearson Ford (US, auto dealership) — DLS June 2026; attack est. May 2026
  • Corley Manufacturing (US, manufacturing) — DLS June 2026
  • Dallis Law Firm (US, legal/professional services) — DLS June 2026
  • [July 2026 DLS activity: ~43 cumulative victims tracked by ShellCodeX; last recorded DLS post July 16, 2026; named victims not independently verified this cycle — sourced from ShellCodeX aggregator, 🟥 unverified]
  • [August–September 2026: No confirmed new DLS posts tracked; group appears to have gone quiet since July 16 DLS activity]

Assessment

Play reached 1,200+ cumulative alleged victims as of August 2026 (Black Kite) — a figure that places it among the most prolific groups historically, though Qilin and Akira have surpassed it in 2026 pace. The most recent confirmed DLS post was July 16, 2026; no new Play victims were independently tracked through September 6. The group may be in a temporary operational pause, restructuring, or shifting targeting quietly — consistent with how Play responded to the Dec 2023 / Jun 2025 CISA/FBI advisory attention. The closed-crew model (no RaaS affiliates confirmed) limits exposure to law-enforcement affiliate-flipping operations but also caps scale. If the quiet extends past October 2026 without a confirmed victim, status should be reassessed toward Dormant. SMB and mid-market manufacturing, construction, and professional services firms remain the target profile. Priority defences unchanged: patch VPN appliances (FortiOS, Ivanti) on an emergency cycle; restrict or segment RDP; audit AD for Kerberoastable accounts, weak service passwords, and misconfigured GPOs; verify backup integrity and offline copy availability.

Sources

🗂️ Attacks & victims

All disclosed victims attributed to this actor, newest first.

September 2026

Sep 08 GT Distributors Play Ransomware · law enforcement equipment · US Austin, Texas-based national distributor of tactical gear, firearms accessories and uniforms for law enforcement, military and public-safety agencies; listed on Play's leak site Sep 8 claiming internal data theft. Play uses double extortion (no upfront ransom demand in the leak note); data scope and impact unconfirmed. · Sources: RedPacketSecurity

August 2026

Aug 06 Signature Services Play Ransomware · Business Services · US Play ransomware DLS listing, Aug 6 2026; files encrypted, data exfiltrated · Sources: https://ransomware.live/id/U2lnbmF0dXJlIFNlcnZpY2VzQHBsYXk=
Aug 01 Sigma Plastics Group Play Ransomware · Manufacturing · US Play DLS claim August 1 2026; major US plastics manufacturer. No victim statement; no data published. · Sources: https://www.redpacketsecurity.com/play-ransomware-victim-sigma-plastics-group/
Aug 01 The Butcher Brothers Play Ransomware · Food Processing · US Play DLS claim August 1 2026; US food processing/distribution. No victim statement; no data published; no data volume disclosed. · Sources: https://www.ransomware.live/id/VGhlIEJ1dGNoZXIgQnJvdGhlcnNAcGxheQ==

July 2026

Jul 04 Locati Architects Play Ransomware · architecture · construction/Australia Play DLS claim July 4, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/play · Sources: [ransomware.live]
Jul 04 Silvestri & Associates Insurance Play Ransomware · financial services · insurance/US Play DLS claim July 4, 2026; data leak threatened; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/play-ransomware-targets-silvestri-associates-insurance/ · Sources: [DeXpose]

June 2026

Jun 30 Western Construction Play Ransomware · construction · US Play DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://ransomware.live/id/V2VzdGVybiBDb25zdHJ1Y3Rpb25AcGxheQ== · Sources: [ransomware.live]
Jun 27 Kuhnline Play Ransomware · construction · Germany Play DLS claim June 27, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/id/S3VobmxpbmVAcGxheQ== · https://www.facebook.com/CyberNewsLive/photos/play-claims-to-have-targeted-kuhnline-kuhnlinecom-a-construction-company-this-re/1349093380535328/ · Sources: [ransomware.live] · [Cyber News Live]
Jun 06 Pearson Ford Play Ransomware · auto dealership · US Sources: ransomware.live DLS
Jun 05 Corley Manufacturing Play Ransomware · manufacturing · US Sources: ransomware.live DLS
Jun 05 Dallis Law Firm Play Ransomware · legal · US Sources: ransomware.live DLS
Jun 01 MyPillow Play Ransomware · manufacturing · retail/US payroll, tax, employee-ID data claimed · Sources: Play DLS

← All threat actors · Full victim database →