Overview

Platforms: Windows · Linux
Variants: —
Extensions: .play
ATT&CK software: AdFind · Cobalt Strike · SystemBC · GootLoader · Mimikatz
Initial access: Valid Accounts · Exploit Public-Facing Application
Top countries: US · CA · GB · DE · IT
Observed sectors: Other · Non-Profit · Manufacturing · Construction · Technology
Tracked victims: 1,301

Victims

Sys-kool CLAIMED
September 10, 2026 United States Non-Profit 3 tracker sources
Non-Profit organization in United States.
Grunthal Welding & Supplies CLAIMED
September 10, 2026 Canada Manufacturing 3 tracker sources
Manufacturing organization in Canada.
Red Star Oil CLAIMED
September 8, 2026 United States Energy & Utilities 3 tracker sources
Energy & Utilities organization in United States.
GT Distributors CLAIMED
September 8, 2026 United States Retail & E-Commerce 3 tracker sources
Retail & E-Commerce organization in United States.
MEQ CLAIMED
August 31, 2026 Canada 3 tracker sources
Organization in Canada.
Show more victims (12)
Meteor Group CLAIMED
August 31, 2026 Germany Other 3 tracker sources
Other organization in Germany.
KRC Machine Tool Solutions CLAIMED
August 31, 2026 United States Manufacturing 3 tracker sources
Manufacturing organization in United States.
Figgins Family Wine Estates CLAIMED
August 31, 2026 United States Agriculture & Food 3 tracker sources
Agriculture & Food organization in United States.
Latoplast CLAIMED
August 20, 2026 Canada 3 tracker sources
Organization in Canada.
Be Media CLAIMED
August 20, 2026 United States Media & Entertainment 3 tracker sources
Media & Entertainment organization in United States.
Coltrane Systems CLAIMED
August 18, 2026 United States 3 tracker sources
Organization in United States.
Woodhaven Association CLAIMED
August 17, 2026 United States 3 tracker sources
Organization in United States.
Marconi Industrial Services CLAIMED
August 9, 2026 Italy 3 tracker sources
Organization in Italy.
MIE Solutions CLAIMED
August 9, 2026 United States 3 tracker sources
Organization in United States.
Rilpa Enterprises CLAIMED
August 9, 2026 Canada 3 tracker sources
Organization in Canada.
Signature Services CLAIMED
August 6, 2026 United States 3 tracker sources
Organization in United States.
GCATS Investments CLAIMED
August 6, 2026 United States Financial Services 3 tracker sources
Financial Services organization in United States.

Operational Activity

Recent Observations

Continued Play victim claims
September 2026
Ransomware activity
New Play victim claims continued to appear on the operation's data leak site during September 2026.
Play activity increases in Q1 2026
March 2026
Ransomware activity
Play published 121 victims during Q1 2026, a 64 percent increase compared with Q4 2025.
Approximately 900 affected entities
May 2025
Operational scale
The FBI reported awareness of approximately 900 entities allegedly affected by Play ransomware as of May 2025.
Rackspace Hosted Exchange attack
December 2022
Major incident
Play compromised Rackspace Hosted Exchange using a previously unknown exploit chain and caused a prolonged service disruption.

TTPs

ATT&CK coverage: 8 techniques
T1078 Valid Accounts
VERIFIED
Play actors obtain and abuse existing account credentials, including those for RDP and VPN services, to gain initial access to victim environments.
T1190 Exploit Public-Facing Application
VERIFIED
Play actors exploit vulnerabilities in internet-facing systems, specifically mentioning Microsoft Exchange Server (ProxyNotShell) and Fortinet SSL VPN, to gain access.
T1059.001 PowerShell
VERIFIED
Play uses PowerShell during post-exploitation activity, including encoded scripts, to facilitate lateral movement and execution of malicious payloads.
Show more TTPs (5)
T1562.001 Impair Defenses
VERIFIED
Play uses tools such as GMER, IOBit Uninstaller, and PowerTool to terminate or disable endpoint security products and antivirus software.
T1560.001 Archive via Utility
VERIFIED
Play utilizes legitimate utilities such as WinRAR to compress and stage stolen data prior to exfiltration.
T1486 Data Encrypted for Impact
VERIFIED
Play encrypts victim systems using a custom ransomware binary that employs hybrid AES-RSA encryption and intermittent encryption techniques to speed up the process.
T1021.001 Remote Desktop Protocol
VERIFIED
Play actors frequently utilize Remote Desktop Protocol (RDP) for lateral movement within compromised networks.
T1083 File and Directory Discovery
VERIFIED
Play actors employ tools such as AdFind and other native Windows commands to discover files and directories of interest on victim systems.

CVEs

The Play ransomware group exploited this privilege-escalation vulnerability as part of a remote code execution chain (referred to as OWASSRF) to gain initial access to Rackspace's Hosted Exchange environment.
Associated since: December 2022
Initial access brokers with ties to Play ransomware operators exploited this path traversal vulnerability in SimpleHelp RMM software to conduct remote code execution at U.S.-based entities.
Associated since: January 2025
The Balloonfly group, responsible for distributing Play ransomware, exploited this Windows Common Log File System driver privilege-escalation vulnerability as a zero-day.
Associated since: April 2025

Infrastructure

Leak site
Play ransomware group maintains a dedicated Tor-based leak site utilized to publish victim names and exfiltrated data as part of their double-extortion operational model.
ONLINE
Last checked: September 17, 2026
Victim communication
The group employs victim-specific email addresses and direct communication methods, including telephone contact, to facilitate ransom negotiations.

Attribution

Play VERIFIED
Vendor tracking name
Play, also known as PlayCrypt, is a ransomware group that has been active since June 2022. The group is primarily tracked under its self-identified name.

Affiliates

No affiliate information available.

Timeline

2025-05-01
FBI reports 900 entities affected
The FBI reported that approximately 900 entities had been affected by Play ransomware since its inception.
2025-04-01
Windows zero-day exploitation
The threat actor known as Balloonfly exploited CVE-2025-29824 as a zero-day in intrusions linked to Play ransomware activity.
2022-12-02
Rackspace Hosted Exchange compromise
Play ransomware actors compromised Rackspace Hosted Exchange environments utilizing CVE-2022-41080.
Show more events (1)
2022-06-01
Play ransomware emerges
Play ransomware, also known as Playcrypt, was first observed targeting organizations with its initial ransom notes.

Sources

Play — G1040
MITRE ATT&CK
Framework
#StopRansomware: Play Ransomware
FBI, CISA, and ASD's ACSC
Show more sources (26)