Play is a financially motivated ransomware group active since June 2022. It is reported as a closed operation that uses valid accounts, exposed remote services, and vulnerability exploitation before discovery, credential theft, data exfiltration, and intermittent encryption. Windows and VMware ESXi variants support a double-extortion model backed by a Tor leak site and direct pressure on victims.
A prolific double-extortion group with per-victim payload builds, extensive use of legitimate administration tools, and Windows plus ESXi encryption capability.
Actor class
Closed ransomware operation
Motivation
Financial
Facts
Play is also associated with the ransomware-family name Playcrypt.
The operation is presumed to be closed rather than an openly advertised affiliate program.
FBI was aware of approximately 900 allegedly affected entities as of May 2025.
Activity timeline
First observed
June 2022
Status
Active
Status as of
2025-06-04
Facts
The updated advisory includes investigations and indicators observed as recently as January 2025.
Play was among the most active ransomware groups in 2024.
Operational playbook
Stages
Acquire or abuse valid accounts and exposed RDP or VPN services, or exploit public-facing applications.
Enumerate Active Directory, network settings, hosts, security software, credentials, and privilege-escalation paths.
Disable endpoint protections and clear logs with a mix of custom and legitimate tools.
Move laterally and distribute payloads with Cobalt Strike, SystemBC, PsExec, and Group Policy.
Split and compress stolen data with WinRAR and transfer it with WinSCP.
Encrypt Windows or ESXi workloads and pressure victims through email, phone calls, and threatened Tor publication.
Initial access and identity targets
Methods
Valid accounts reportedly purchased through criminal markets
RDP and VPN external remote services
FortiOS exploitation
Microsoft Exchange ProxyNotShell exploitation
SimpleHelp remote monitoring and management exploitation
Capabilities and evasion
Facts
Play recompiles the ransomware binary for individual attacks, reducing the value of payload-hash-only detection.
Windows encryption uses an AES-RSA hybrid design with intermittent encryption and appends .PLAY.
The ESXi variant powers off virtual machines, targets common VM disk and state files, and uses AES-256.
Grixba supports network and security-product discovery; Play has also used Cobalt Strike and SystemBC for command and control.
Observed defense-impairment tools include GMER, IOBit, PowerTool, and custom HRsword-related components.
Infrastructure patterns
Facts
Each victim receives a unique gmx.de or web.de email address for negotiation.
Non-paying victims are threatened with publication on a Tor-hosted data-leak site.
Plink has been used to establish persistent SSH tunnels.
Communication and pressure channels
Facts
Ransom notes initially direct victims to contact the group rather than stating the demand or payment instructions.
Channels
Victim-specific GMX or Web.de email
Telephone pressure
Tor data-leak site
Observed targeting
Targeting, not victimization. The regional and sector summary describes reported impact. The profile's live victim table contains leak-site claims and labels them separately from confirmed incidents.
Facts
Reported impact spans business, government, critical infrastructure, healthcare, and media organizations.
Observed regions include North America, South America, and Europe.
Defender guidance
Measures
Prioritize remediation of known exploited vulnerabilities in FortiOS, Microsoft Exchange, SimpleHelp, and other internet-facing services.
Require MFA for webmail, VPN, remote access, and privileged accounts.
Monitor for Grixba, AdFind, PsExec, Cobalt Strike, SystemBC, unusual Group Policy changes, and encoded PowerShell in context rather than treating every administration tool as malicious.
Alert on WinRAR staging followed by WinSCP transfers and on unexpected GMX or Web.de contact in ransomware notes.
Segment networks and isolate ESXi management interfaces, while maintaining tested offline backups and a recovery plan.
Activity timeline
A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.
Cataloged
IdentityTracking identifier: G1040
Reviewed identity mapping approved on this date.
First listed
Victim claimSys-kool listed by Play
Actor-claimed victim evidence. This listing is not independent confirmation of compromise.
Actor Claimed
First listed
Victim claimGrunthal Welding & Supplies listed by Play
Actor-claimed victim evidence. This listing is not independent confirmation of compromise.
Actor Claimed
First listed
Victim claimRed Star Oil listed by Play
Actor-claimed victim evidence. This listing is not independent confirmation of compromise.
Actor Claimed
First listed
Victim claimGT Distributors listed by Play
Actor-claimed victim evidence. This listing is not independent confirmation of compromise.
Actor Claimed
First listed
Victim claimMEQ listed by Play
Actor-claimed victim evidence. This listing is not independent confirmation of compromise.
Actor Claimed
First listed
Victim claimFiggins Family Wine Estates listed by Play
Actor-claimed victim evidence. This listing is not independent confirmation of compromise.
Actor Claimed
First listed
Victim claimKRC Machine Tool Solutions listed by Play
Actor-claimed victim evidence. This listing is not independent confirmation of compromise.
Actor Claimed
First listed
Victim claimMeteor Group listed by Play
Actor-claimed victim evidence. This listing is not independent confirmation of compromise.
Actor Claimed
First listed
Victim claimBe Media listed by Play
Actor-claimed victim evidence. This listing is not independent confirmation of compromise.
Actor Claimed
First listed
Victim claimLatoplast listed by Play
Actor-claimed victim evidence. This listing is not independent confirmation of compromise.
Actor Claimed
First listed
Victim claimColtrane Systems listed by Play
Actor-claimed victim evidence. This listing is not independent confirmation of compromise.
Actor Claimed
First listed
Victim claimBridgeport Capital Services listed by Play
Actor-claimed victim evidence. This listing is not independent confirmation of compromise.
Actor Claimed
First listed
Victim claimSam Pack Auto Group listed by Play
Actor-claimed victim evidence. This listing is not independent confirmation of compromise.
Actor Claimed
Cataloged
Indicator15 indicators cataloged
Types: sha1, sha256, tool.
Cataloged
IdentityAlias: Playcrypt
Reviewed identity mapping approved on this date.
First listed
Victim claimMIE Solutions listed by Play
Actor-claimed victim evidence. This listing is not independent confirmation of compromise.
Actor Claimed
First listed
Victim claimRilpa Enterprises listed by Play
Actor-claimed victim evidence. This listing is not independent confirmation of compromise.
Actor Claimed
First listed
Victim claimMarconi Industrial Services listed by Play
Actor-claimed victim evidence. This listing is not independent confirmation of compromise.
Actor Claimed
First listed
Victim claimSignature Services listed by Play
Actor-claimed victim evidence. This listing is not independent confirmation of compromise.
Actor Claimed
First listed
Victim claimGCATS Investments listed by Play
Actor-claimed victim evidence. This listing is not independent confirmation of compromise.
Actor Claimed
First listed
Victim claimPlatinum Group listed by Play
Actor-claimed victim evidence. This listing is not independent confirmation of compromise.
Actor Claimed
Claimed
Victim claimWoodhaven Association listed by Play
Actor-claimed victim evidence. This listing is not independent confirmation of compromise.
Actor Claimed
First listed
Victim claimFirst Tek listed by Play
Actor-claimed victim evidence. This listing is not independent confirmation of compromise.
Actor Claimed
First listed
Victim claimPreferred Financial Group listed by Play
Actor-claimed victim evidence. This listing is not independent confirmation of compromise.
Actor Claimed
The interactive view includes 103 dated events with category filters and paging.
Identity and attribution
Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.
Name map
PlayCanonical Name
PlaycryptAlias
G1040Tracking Id
Loading CVEs, techniques, indicators, malware, victims, and activity...