Play is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a double-extortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.(Citation: CISA Play Ransomware Advisory December 2023)(Citation: Trend Micro Ransomware Spotlight Play July 2023)
Executive Summary
Play is a ransomware group active since at least November 2022, deploying Playcrypt ransomware against various sectors globally. They employ double extortion tactics, encrypting systems after exfiltrating data, and are suspected to operate as a closed group with high sophistication. Their campaigns have targeted businesses, governments, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe.
Goals & Targeting
Play's primary goals appear to be financial gain through ransom payments, coupled with the disruption of targeted organizations. They focus on sectors with high systemic importance or those they perceive as having limited defenses, such as critical infrastructure, healthcare, and small-to-medium businesses. Their targeting strategy suggests a preference for geographic regions with weaker cybersecurity frameworks and a focus on maximizing payouts while minimizing operational risk.
Enhanced Description
Play is a sophisticated ransomware group that has been active since at least November 2022. The group operates using a double-extortion model, where they both encrypt systems and exfiltrate data before demanding ransoms for its release. Playcrypt, their primary malware, targets critical sectors such as business, government, healthcare, media, and critical infrastructure in North America, South America, and Europe. Security researchers have observed their campaigns using a combination of phishing, remote exploitation, and brute-force attacks to gain initial access to victim networks. Once inside, they deploy Playcrypt to encrypt files and use tools like Cobalt Strike for lateral movement and persistence. Their operations demonstrate both technical proficiency and strategic planning, aligning with the broader trend of ransomware groups increasingly targeting critical infrastructure and healthcare sectors for maximum impact.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Play has conducted numerous campaigns targeting a wide range of industries, including healthcare providers and construction companies. Their operational tempo suggests a focus on scalability and efficiency, often compromising multiple victims within short periods. Notable campaigns include attacks on entities such as Barnes Solicitors LLP, Colorado Construction, and Lucky Look. Play's ability to adapt their tactics, such as using Cobalt Strike for lateral movement and employing obfuscation techniques, highlights their operational maturity. Their victims are typically organizations with limited defenses or those in sectors where downtime has significant consequences.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
There is a high confidence in Play's association with the described activities due to consistent reporting from multiple sources, including CISA and Trend Micro. However, specific details about their internal structure and exact geographic origin remain unclear, which introduces some uncertainty in their long-term strategic goals.
play: Rilpa Enterprises
Ransomware attack attributed to play. | Sector: Not Found | Website: www.helis.com | Canada | Source: https://www.ransomware.live/id/UmlscGEgRW50ZXJwcmlzZXNAcGxheQ==
Aug 9, 2026
TLP:CLEARplay: First Tek
Ransomware attack attributed to play. | Country: TW | Sector: Technology | Website: www.first-tek.com | United States | Source: https://www.ransomware.live/id/Rmlyc3QgVGVrQHBsYXk=
Aug 4, 2026
TLP:CLEARplay: The DeBruler
Ransomware attack attributed to play. | Country: MT | Sector: Not Found | Website: www.tax-mt.com | United States | Source: https://www.ransomware.live/id/VGhlIERlQnJ1bGVyQHBsYXk=
Jul 23, 2026
TLP:CLEARplay: Tax MT
Ransomware attack attributed to play. | Country: MT | Sector: Business Services | Website: www.tax-mt.com | United States | Source: https://www.ransomware.live/id/VGF4IE1UQHBsYXk=
Jul 21, 2026
TLP:CLEARplay: Wring Group
Ransomware attack attributed to play. | Country: GB | Sector: Not Found | Website: www.wringgroup.co.uk | United Kingdom | Source: https://www.ransomware.live/id/V3JpbmcgR3JvdXBAcGxheQ==
Jul 16, 2026
TLP:CLEARplay: Andorra Life
Ransomware attack attributed to play. | Country: AD | Sector: Healthcare | Website: www.andorralife.com | United States | Source: https://www.ransomware.live/id/QW5kb3JyYSBMaWZlQHBsYXk=
Jul 16, 2026
TLP:CLEARplay: AG Scholtes
Ransomware attack attributed to play. | Country: NL | Sector: Manufacturing | Website: www.agscholtes.nl | Netherlands | Source: https://www.ransomware.live/id/QUcgU2Nob2x0ZXNAcGxheQ==
Jul 16, 2026
TLP:CLEARplay: Kevin Bao Lenguyen
Ransomware attack attributed to play. | Sector: Not Found | Website: www.kblaa.com | United States | Source: https://www.ransomware.live/id/S2V2aW4gQmFvIExlbmd1eWVuQHBsYXk=
Jul 7, 2026
TLP:CLEARplay: J&J Gaming
Ransomware attack attributed to play. | Country: US | Sector: Consumer Services | Website: www.jjgaming.com | United States | Source: https://www.ransomware.live/id/SiZKIEdhbWluZ0BwbGF5
Jun 27, 2026
TLP:CLEARplay: Kuhnline
Ransomware attack attributed to play. | Country: DE | Sector: Not Found | Website: www.kuhnline.com | United States | Source: https://www.ransomware.live/id/S3VobmxpbmVAcGxheQ==
Jun 27, 2026
TLP:CLEARplay: eurOptimum
Ransomware attack attributed to play. | Country: DE | Sector: Technology | Website: www.europtimum.com | United States | Source: https://www.ransomware.live/id/ZXVyT3B0aW11bUBwbGF5
Jun 17, 2026
TLP:CLEARplay: Greg Crosslin
Ransomware attack attributed to play. | Country: US | Sector: Not Found | Website: www.destinlegal.com | United States | Source: https://www.ransomware.live/id/R3JlZyBDcm9zc2xpbkBwbGF5
Jun 17, 2026
TLP:CLEARplay: The Chapel
Ransomware attack attributed to play. | Country: US | Sector: Not Found | Website: www.thechapel.com | United States | Source: https://www.ransomware.live/id/VGhlIENoYXBlbEBwbGF5
May 29, 2026
TLP:CLEARplay: Corley MFG
Ransomware attack attributed to play. | Country: US | Sector: Manufacturing | Website: www.corleymfg.com | United States | Source: https://www.ransomware.live/id/Q29ybGV5IE1GR0BwbGF5
May 29, 2026
TLP:CLEARplay: MyPillow
Ransomware attack attributed to play. | Country: US | Sector: Consumer Services | Website: www.mypillow.com | United States | Source: https://www.ransomware.live/id/TXlQaWxsb3dAcGxheQ==
May 25, 2026
TLP:CLEARplay: Zuther Hautmann
Ransomware attack attributed to play. | Country: DE | Sector: Not Found | Website: www.z-h.de | United States | Source: https://www.ransomware.live/id/WnV0aGVyIEhhdXRtYW5uQHBsYXk=
May 19, 2026
TLP:CLEARplay: Ashcroft Homes
Ransomware attack attributed to play. | Country: CA | Sector: Construction | Website: www.ashcrofthomes.ca | Canada | Source: https://www.ransomware.live/id/QXNoY3JvZnQgSG9tZXNAcGxheQ==
May 12, 2026
TLP:CLEARplay: Morphosis
Ransomware attack attributed to play. | Country: US | Sector: Technology | Website: www.morphosis.com | United States | Source: https://www.ransomware.live/id/TW9ycGhvc2lzQHBsYXk=
Apr 6, 2026
TLP:CLEARplay: Sokolin
Ransomware attack attributed to play. | Country: US | Sector: Consumer Services | Website: www.sokolin.com | United States | Source: https://www.ransomware.live/id/U29rb2xpbkBwbGF5
Apr 4, 2026
TLP:CLEARplay: Lucky Look
Ransomware attack attributed to play. | Country: DE | Sector: Consumer Services | Website: www.lucky-look-media.de | Germany | Source: https://www.ransomware.live/id/THVja3kgTG9va0BwbGF5
Mar 30, 2026
TLP:CLEARplay: Brokk
Ransomware attack attributed to play. | Country: SE | Sector: Manufacturing | Website: www.brokk.com | Sweden | Source: https://www.ransomware.live/id/QnJva2tAcGxheQ==
Mar 24, 2026
TLP:CLEARplay: Specflue
Ransomware attack attributed to play. | Country: GB | Sector: Manufacturing | Website: www.specflue.com | United Kingdom | Source: https://www.ransomware.live/id/U3BlY2ZsdWVAcGxheQ==
Mar 23, 2026
TLP:CLEARplay: Pinnacle
Ransomware attack attributed to play. | Country: US | Sector: Not Found | Website: www.pinnacle.tax | United States | Source: https://www.ransomware.live/id/UGlubmFjbGVAcGxheQ==
Mar 16, 2026
TLP:CLEARplay: Gsolutionz
Ransomware attack attributed to play. | Country: US | Sector: Technology | Website: www.gsolutionz.com | United States | Source: https://www.ransomware.live/id/R3NvbHV0aW9uekBwbGF5
Mar 14, 2026
TLP:CLEARplay: Select Tool
Ransomware attack attributed to play. | Country: CA | Sector: Manufacturing | Website: www.selecttool.com | Canada | Source: https://www.ransomware.live/id/U2VsZWN0IFRvb2xAcGxheQ==
Mar 1, 2026
TLP:CLEARplay: Cabka
Ransomware attack attributed to play. | Country: DE | Sector: Manufacturing | Website: www.cabka.com | Germany | Source: https://www.ransomware.live/id/Q2Fia2FAcGxheQ==
Feb 27, 2026
TLP:CLEARNo observed data linked yet.
26
Techniques
3
Tools
109
Campaigns
361
IOCs
0
Observed Data
13
Tactics