Play Ransomware — Ransomware Profile
Play is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a double-extortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.Also tracked as
Play, Playcrypt
Tools & malware
- AdFind Network Reconnaissance
- BloodHound Network Reconnaissance
- Cobalt Strike Adversary Simulation
- Empire Post-Exploitation Framework
- Mimikatz Credential Harvesting
- Nltest Network Reconnaissance
- Playcrypt Ransomware
- PsExec Remote Execution
- Wevtutil Discovery
Recent claimed victims
- Record Go Alquiler 2026-07-23
- Restaurant Depot 2026-07-23
- The DeBruler 2026-07-23
- Tax MT 2026-07-21
- Kreysler & Associates 2026-07-21
- Boston Electric and Telephone 2026-07-16
- Wring Group 2026-07-16
- AG Scholtes 2026-07-16
- Andorra Life 2026-07-16
- Svensk Direktreklam 2026-07-16
- Preneed Funeral Programs 2026-07-07
- Kevin Bao Lenguyen 2026-07-07
- United Infrastructure 2026-07-07
- Locati Architects 2026-07-04
- Silvestri & Associates Insurance 2026-07-04
- Western Construction 2026-06-30
- J&J Gaming 2026-06-27
- Kuhnline 2026-06-27
- Benchmark Industrial Supply 2026-06-26
- Integrated Technologies 2026-06-17
- eurOptimum 2026-06-17
- Greg Crosslin 2026-06-17
- Mundt and Associates 2026-06-10
- Rainbow Distributors USA 2026-06-10
- Pearson Ford 2026-06-06