Play (PlayCrypt) Ransomware

Description Summary

Play (also known as PlayCrypt) ransomware emerged in mid-2022 and has become one of the most active double-extortion families. Its operators do not run an affiliate program in the classic RaaS sense and instead conduct intrusions themselves; victims are emailed an .onion contact rather than given a ransom note with an embedded URL. As of October 2023 the FBI assessed Play had impacted approximately 300 entities globally.

Threat Actor

Believed to be operated by a closed Russian-speaking team. Initial access has frequently come from FortiOS (CVE-2018-13379, CVE-2020-12812) and Microsoft Exchange ProxyNotShell (CVE-2022-41040, CVE-2022-41082) exploits.

Technical Indicators

Encryption Extension
.play
Encryption Algorithm
AES-256 + RSA
Ransom Note Name
ReadMe.txt
Targeted Industries
Government, Critical infrastructure, Healthcare, Education, Manufacturing
First Seen
June 2022
Last Seen
Active
Geographical Location
Americas, Europe, Australia

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Initial Access x 4 T1566 Phishing
T1190 Exploit Public-Facing Application
T1078 Valid Accounts
T1190 Exploit Public-Facing Application (Fortinet, Exchange)
Execution x 1 T1059 Command and Scripting Interpreter
Execution Persistence x 1 T1053 Scheduled Task/Job
Defense Evasion x 2 T1562.001 Disable or Modify Tools
T1070.004 File Deletion
Discovery x 2 T1083 File and Directory Discovery
T1082 System Information Discovery
Lateral Movement x 2 T1021.001 Remote Services: RDP
T1021.002 SMB/Windows Admin Shares
Exfiltration x 2 T1041 Exfiltration Over C2 Channel
T1567.002 Exfiltration to Cloud Storage
Impact x 4 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery
T1489 Service Stop
T1486 Intermittent Encryption