— Play¶
Threat-actor battle card · maintained from public sources · last updated 2026-09-06 · also known as PlayCrypt
Overview¶
Play (also known as PlayCrypt) is a financially motivated ransomware group active since June 2022. The FBI and CISA documented approximately 900 confirmed victims by May 2025, spanning North America, South America, and Europe. The group has consistently ranked in the global top-10 and directs roughly 85% of its attacks against US organisations. It operates a double-extortion model — exfiltrating data before encrypting, then threatening publication on a Tor-hosted leak site — but with an unusual ransom-note design: no demand or payment details are included; victims are instructed to contact the group via email only. No RaaS affiliate programme has been confirmed; Play appears to operate as a closed crew. A joint CISA/FBI/ASD ACSC advisory (AA23-352A) was issued December 2023 and updated June 2025.
Tradecraft¶
- Initial access: Exploits VPN appliance vulnerabilities — primarily FortiOS and Ivanti Connect Secure flaws — as well as valid credentials and exposed RDP. Optimised for speed against SMBs (<250 employees), achieving full domain compromise in hours.
- Recon: Grixba (custom Play-built info-stealer) to enumerate network and credential data; AdFind for Active Directory queries; BloodHound for AD attack-path mapping. Group identifies misconfigured GPOs, weak service accounts, and Kerberoastable accounts rapidly.
- Defence evasion: GMER, IOBit, PowerTool to delete logs and disable security products; PowerShell to disable Microsoft Defender. Each ransomware binary is recompiled per attack with a unique hash to bypass signature-based detection.
- Lateral movement: PsExec for remote execution across the network.
- Credential access: Mimikatz for domain administrator credential theft.
- Encryption: Appends .PLAY extension; Windows and ESXi/VMware variants both operational.
- Extortion channel: Victims receive ransom note with an @gmx.de or @web.de email contact only. On deadline expiry, data is published to the group's Tor-hosted DLS.
Notable recent victims¶
- Western Construction (US, construction) — DLS June 30, 2026; 🟥 unverified
- Kuhnline (DE, construction) — DLS June 27, 2026; data scope unconfirmed; 🟥 unverified
- MyPillow (US, manufacturing/retail) — DLS June 2026
- Pearson Ford (US, auto dealership) — DLS June 2026; attack est. May 2026
- Corley Manufacturing (US, manufacturing) — DLS June 2026
- Dallis Law Firm (US, legal/professional services) — DLS June 2026
- [July 2026 DLS activity: ~43 cumulative victims tracked by ShellCodeX; last recorded DLS post July 16, 2026; named victims not independently verified this cycle — sourced from ShellCodeX aggregator, 🟥 unverified]
- [August–September 2026: No confirmed new DLS posts tracked; group appears to have gone quiet since July 16 DLS activity]
Assessment¶
Play reached 1,200+ cumulative alleged victims as of August 2026 (Black Kite) — a figure that places it among the most prolific groups historically, though Qilin and Akira have surpassed it in 2026 pace. The most recent confirmed DLS post was July 16, 2026; no new Play victims were independently tracked through September 6. The group may be in a temporary operational pause, restructuring, or shifting targeting quietly — consistent with how Play responded to the Dec 2023 / Jun 2025 CISA/FBI advisory attention. The closed-crew model (no RaaS affiliates confirmed) limits exposure to law-enforcement affiliate-flipping operations but also caps scale. If the quiet extends past October 2026 without a confirmed victim, status should be reassessed toward Dormant. SMB and mid-market manufacturing, construction, and professional services firms remain the target profile. Priority defences unchanged: patch VPN appliances (FortiOS, Ivanti) on an emergency cycle; restrict or segment RDP; audit AD for Kerberoastable accounts, weak service passwords, and misconfigured GPOs; verify backup integrity and offline copy availability.
Sources¶
- CISA #StopRansomware: Play Ransomware (AA23-352A, Dec 2023)
- CISA/FBI/ASD Updated Play Advisory, June 2025
- FBI StopRansomware Play Advisory (IC3 PDF, Jun 2025)
- HIPAA Journal — Updated Play Advisory: Victim Count Reaches 900
- Cybersecurity Dive — FBI/CISA warn Play targeting critical infrastructure
- SOCRadar — Dark Web Profile: Play Ransomware
- Huntress — Play Threat Actor Profile
- ShellCodeX — Play Group Profile & Victim Tracker
🗂️ Attacks & victims¶
All disclosed victims attributed to this actor, newest first.
September 2026
August 2026
July 2026
June 2026