Description Summary
Play (also known as PlayCrypt) ransomware emerged in mid-2022 and has become one of the most active double-extortion families. Its operators do not run an affiliate program in the classic RaaS sense and instead conduct intrusions themselves; victims are emailed an .onion contact rather than given a ransom note with an embedded URL. As of October 2023 the FBI assessed Play had impacted approximately 300 entities globally.
Threat Actor
Believed to be operated by a closed Russian-speaking team. Initial access has frequently come from FortiOS (CVE-2018-13379, CVE-2020-12812) and Microsoft Exchange ProxyNotShell (CVE-2022-41040, CVE-2022-41082) exploits.
Technical Indicators
Encryption Extension
.play
Encryption Algorithm
AES-256 + RSA
Ransom Note Name
ReadMe.txt
Targeted Industries
Government, Critical infrastructure, Healthcare, Education, Manufacturing
First Seen
June 2022
Last Seen
Active
Geographical Location
Americas, Europe, Australia
MITRE ATT&CK Matrix
| Tactic | TTP | Technique Name |
|---|---|---|
| Initial Access x 4 | T1566 | Phishing |
| T1190 | Exploit Public-Facing Application | |
| T1078 | Valid Accounts | |
| T1190 | Exploit Public-Facing Application (Fortinet, Exchange) | |
| Execution x 1 | T1059 | Command and Scripting Interpreter |
| Execution Persistence x 1 | T1053 | Scheduled Task/Job |
| Defense Evasion x 2 | T1562.001 | Disable or Modify Tools |
| T1070.004 | File Deletion | |
| Discovery x 2 | T1083 | File and Directory Discovery |
| T1082 | System Information Discovery | |
| Lateral Movement x 2 | T1021.001 | Remote Services: RDP |
| T1021.002 | SMB/Windows Admin Shares | |
| Exfiltration x 2 | T1041 | Exfiltration Over C2 Channel |
| T1567.002 | Exfiltration to Cloud Storage | |
| Impact x 4 | T1486 | Data Encrypted for Impact |
| T1490 | Inhibit System Recovery | |
| T1489 | Service Stop | |
| T1486 | Intermittent Encryption |