Overview
Platforms:
Windows · Linux
Variants:
—
Extensions:
.play
ATT&CK software:
AdFind · Cobalt Strike · SystemBC · GootLoader · Mimikatz
Initial access:
Valid Accounts · Exploit Public-Facing Application
Top countries:
US · CA · GB · DE · IT
Observed sectors:
Other · Non-Profit · Manufacturing · Construction · Technology
Tracked victims:
1,301
Victims
Sys-kool
CLAIMED
Non-Profit organization in United States.
Grunthal Welding & Supplies
CLAIMED
Manufacturing organization in Canada.
Red Star Oil
CLAIMED
Energy & Utilities organization in United States.
GT Distributors
CLAIMED
Retail & E-Commerce organization in United States.
MEQ
CLAIMED
Organization in Canada.
Show more victims (12)
Meteor Group
CLAIMED
Other organization in Germany.
KRC Machine Tool Solutions
CLAIMED
Manufacturing organization in United States.
Figgins Family Wine Estates
CLAIMED
Agriculture & Food organization in United States.
Latoplast
CLAIMED
Organization in Canada.
Be Media
CLAIMED
Media & Entertainment organization in United States.
Coltrane Systems
CLAIMED
Organization in United States.
Woodhaven Association
CLAIMED
Organization in United States.
Marconi Industrial Services
CLAIMED
Organization in Italy.
MIE Solutions
CLAIMED
Organization in United States.
Rilpa Enterprises
CLAIMED
Organization in Canada.
Signature Services
CLAIMED
Organization in United States.
GCATS Investments
CLAIMED
Financial Services organization in United States.
Operational Activity
Recent Observations
Continued Play victim claims
September 2026
Ransomware activity
New Play victim claims continued to appear on the operation's data leak site during September 2026.
Play activity increases in Q1 2026
March 2026
Ransomware activity
Play published 121 victims during Q1 2026, a 64 percent increase compared with Q4 2025.
Approximately 900 affected entities
May 2025
Operational scale
The FBI reported awareness of approximately 900 entities allegedly affected by Play ransomware as of May 2025.
Rackspace Hosted Exchange attack
December 2022
Major incident
Play compromised Rackspace Hosted Exchange using a previously unknown exploit chain and caused a prolonged service disruption.
TTPs
ATT&CK coverage:
8 techniques
T1078
Valid Accounts
VERIFIEDPlay actors obtain and abuse existing account credentials, including those for RDP and VPN services, to gain initial access to victim environments.
T1190
Exploit Public-Facing Application
VERIFIEDPlay actors exploit vulnerabilities in internet-facing systems, specifically mentioning Microsoft Exchange Server (ProxyNotShell) and Fortinet SSL VPN, to gain access.
T1059.001
PowerShell
VERIFIEDPlay uses PowerShell during post-exploitation activity, including encoded scripts, to facilitate lateral movement and execution of malicious payloads.
Show more TTPs (5)
T1562.001
Impair Defenses
VERIFIEDPlay uses tools such as GMER, IOBit Uninstaller, and PowerTool to terminate or disable endpoint security products and antivirus software.
T1560.001
Archive via Utility
VERIFIEDPlay utilizes legitimate utilities such as WinRAR to compress and stage stolen data prior to exfiltration.
T1486
Data Encrypted for Impact
VERIFIEDPlay encrypts victim systems using a custom ransomware binary that employs hybrid AES-RSA encryption and intermittent encryption techniques to speed up the process.
T1021.001
Remote Desktop Protocol
VERIFIEDPlay actors frequently utilize Remote Desktop Protocol (RDP) for lateral movement within compromised networks.
T1083
File and Directory Discovery
VERIFIEDPlay actors employ tools such as AdFind and other native Windows commands to discover files and directories of interest on victim systems.
CVEs
The Play ransomware group exploited this privilege-escalation vulnerability as part of a remote code execution chain (referred to as OWASSRF) to gain initial access to Rackspace's Hosted Exchange environment.
Associated since:
December 2022
Initial access brokers with ties to Play ransomware operators exploited this path traversal vulnerability in SimpleHelp RMM software to conduct remote code execution at U.S.-based entities.
Associated since:
January 2025
The Balloonfly group, responsible for distributing Play ransomware, exploited this Windows Common Log File System driver privilege-escalation vulnerability as a zero-day.
Associated since:
April 2025
Infrastructure
Leak site
Play ransomware group maintains a dedicated Tor-based leak site utilized to publish victim names and exfiltrated data as part of their double-extortion operational model.
ONLINE
Last checked:
September 17, 2026
Victim communication
The group employs victim-specific email addresses and direct communication methods, including telephone contact, to facilitate ransom negotiations.
Attribution
Play
VERIFIED
Vendor tracking name
Play, also known as PlayCrypt, is a ransomware group that has been active since June 2022. The group is primarily tracked under its self-identified name.
Affiliates
No affiliate information available.
Timeline
2025-05-01
FBI reports 900 entities affected
The FBI reported that approximately 900 entities had been affected by Play ransomware since its inception.
2025-04-01
Windows zero-day exploitation
The threat actor known as Balloonfly exploited CVE-2025-29824 as a zero-day in intrusions linked to Play ransomware activity.
2022-12-02
Rackspace Hosted Exchange compromise
Play ransomware actors compromised Rackspace Hosted Exchange environments utilizing CVE-2022-41080.
Show more events (1)
2022-06-01
Play ransomware emerges
Play ransomware, also known as Playcrypt, was first observed targeting organizations with its initial ransom notes.
Sources
#StopRansomware: Play Ransomware
FBI, CISA, and ASD's ACSC
Show more sources (26)
Balloonfly Ransomware Group Leveraged 0-Day in Attack
Broadcom / Symantec
Hosted Exchange Issues — Forensic Investigation Update
Rackspace Technology
Grunthal Welding & Supplies — Play Victim Claim
Cyber Threat Intelligence
Play Ransomware: A Deep Dive
Mandiant
play - Ransomware Tracker
Invaders Cybersecurity
Be Media Data Breach
SOCRadar
Play — Threat Actor Profile
DysruptionHub
Update on Recent Cybersecurity Incident
Rackspace Technology
Rackspace: Play ransomware group behind Hosted Exchange attack
Cybersecurity Dive
Play ransomware group tracker
Ransomware.live
Ransomware Trends Q1 2026
ReliaQuest
#PlayRansomware
CISA
Play Ransomware: A Deep Dive
Mandiant
Jumpy Pisces Engages in Play Ransomware
Palo Alto Networks Unit 42