Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Description

Play is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a double-extortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.(Citation: CISA Play Ransomware Advisory December 2023)(Citation: Trend Micro Ransomware Spotlight Play July 2023)

AI Analysis

· 1 week ago

Executive Summary

Play is a ransomware group active since at least November 2022, deploying Playcrypt ransomware against various sectors globally. They employ double extortion tactics, encrypting systems after exfiltrating data, and are suspected to operate as a closed group with high sophistication. Their campaigns have targeted businesses, governments, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe.

Goals & Targeting

Play's primary goals appear to be financial gain through ransom payments, coupled with the disruption of targeted organizations. They focus on sectors with high systemic importance or those they perceive as having limited defenses, such as critical infrastructure, healthcare, and small-to-medium businesses. Their targeting strategy suggests a preference for geographic regions with weaker cybersecurity frameworks and a focus on maximizing payouts while minimizing operational risk.

Enhanced Description

Play is a sophisticated ransomware group that has been active since at least November 2022. The group operates using a double-extortion model, where they both encrypt systems and exfiltrate data before demanding ransoms for its release. Playcrypt, their primary malware, targets critical sectors such as business, government, healthcare, media, and critical infrastructure in North America, South America, and Europe. Security researchers have observed their campaigns using a combination of phishing, remote exploitation, and brute-force attacks to gain initial access to victim networks. Once inside, they deploy Playcrypt to encrypt files and use tools like Cobalt Strike for lateral movement and persistence. Their operations demonstrate both technical proficiency and strategic planning, aligning with the broader trend of ransomware groups increasingly targeting critical infrastructure and healthcare sectors for maximum impact.

Key Capabilities

  • Ransomware deployment (Playcrypt)
  • Double extortion tactics
  • Data exfiltration
  • Phishing campaigns
  • Remote system exploitation
  • Lateral movement using Cobalt Strike
  • Network persistence strategies

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Defense Evasion
Credential Access
Discovery
Lateral Movement
Exfiltration
Impact

ATT&CK Techniques

T1560.001
T1133
T1587.001
T1190
T1003.001
T1685.005
T1083
T1030
T1059.001
T1588.002
T1078.002
T1518.001
T1059.003
T1027.010
T1070.004
T1018
T1078.003
T1082
T1021.002
T1016
T1657
T1057
T1048
T1016

Software / Tooling

Playcrypt ransomware
Cobalt Strike
Windows Command Shell
PowerShell
LSASS Memory Dumping Tools
Process Discovery Tools

Campaigns & Victims

Play has conducted numerous campaigns targeting a wide range of industries, including healthcare providers and construction companies. Their operational tempo suggests a focus on scalability and efficiency, often compromising multiple victims within short periods. Notable campaigns include attacks on entities such as Barnes Solicitors LLP, Colorado Construction, and Lucky Look. Play's ability to adapt their tactics, such as using Cobalt Strike for lateral movement and employing obfuscation techniques, highlights their operational maturity. Their victims are typically organizations with limited defenses or those in sectors where downtime has significant consequences.

IOC Patterns

  • Spear-phishing emails with malicious attachments
  • Use of remote access tools like Cobalt Strike
  • Data exfiltration via alternative protocols (e.g., FTP, HTTP)
  • Scheduled task creation for persistence
  • Volume shadow copy deletion

Recommended Actions

  • Implement robust endpoint detection and response (EDR) solutions to detect Play's TTPs.
  • Monitor for anomalous network activity, particularly remote access attempts and data exfiltration.
  • Regularly backup critical systems and ensure backups are air-gapped or securely stored.
  • Conduct phishing simulations to improve employee awareness of social engineering tactics.
  • Limit RDP and远程桌面服务 (RDS) access to only essential services and use multi-factor authentication.

Suggested Tags

ransomware
double extortion
critical infrastructure
healthcare sector
APT23

Confidence Assessment

There is a high confidence in Play's association with the described activities due to consistent reporting from multiple sources, including CISA and Trend Micro. However, specific details about their internal structure and exact geographic origin remain unclear, which introduces some uncertainty in their long-term strategic goals.

ATT&CK Techniques

Discovery
6 techniques

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 20

References

  1. CISA Play Ransomware Advisory December 2023 — CISA. (2023, December 18). #StopRansomware: Play Ransomware AA23-352A. Retrieved September 24, 2024.
  2. Trend Micro Ransomware Spotlight Play July 2023 — Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

Intel Summary

26

Techniques

3

Tools

109

Campaigns

361

IOCs

0

Observed Data

13

Tactics

Tags

Ransomware
Healthcare Targeting
Critical Infrastructure
Government Targeting
ransomware
double extortion
critical infrastructure
healthcare sector
APT23

Details

MITRE ID
G1040
Type
Unknown
Confidence
90%
First Seen
Nov 26, 2022
Last Seen
Aug 9, 2026
Added
May 2, 2026
STIX ID
intrusion-set--ecbf507f-6786-4121-a4cc-0fd6a8d3a29d
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.