Play Ransomware — Ransomware Profile

Play is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a double-extortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.

Also tracked as

Play, Playcrypt

Tools & malware

Recent claimed victims

Vendor research

Read the full analysis on IntelFusions