← Back to all threat actors

Play

Also known as Playcrypt
Tracked as G1040

Play is a financially motivated ransomware group active since June 2022. It is reported as a closed operation that uses valid accounts, exposed remote services, and vulnerability exploitation before discovery, credential theft, data exfiltration, and intermittent encryption. Windows and VMware ESXi variants support a double-extortion model backed by a Tor leak site and direct pressure on victims.

How we source and review actor profiles
Motivation
ransomware
Sectors
government, critical-infrastructure, healthcare, media-journalism
Status
Active

Threat intelligence assessment

At a glance

A prolific double-extortion group with per-victim payload builds, extensive use of legitimate administration tools, and Windows plus ESXi encryption capability.

Actor class
Closed ransomware operation
Motivation
Financial

Facts

  • Play is also associated with the ransomware-family name Playcrypt.
  • The operation is presumed to be closed rather than an openly advertised affiliate program.
  • FBI was aware of approximately 900 allegedly affected entities as of May 2025.

Activity timeline

First observed
June 2022
Status
Active
Status as of
2025-06-04

Facts

  • The updated advisory includes investigations and indicators observed as recently as January 2025.
  • Play was among the most active ransomware groups in 2024.

Operational playbook

Stages

  • Acquire or abuse valid accounts and exposed RDP or VPN services, or exploit public-facing applications.
  • Enumerate Active Directory, network settings, hosts, security software, credentials, and privilege-escalation paths.
  • Disable endpoint protections and clear logs with a mix of custom and legitimate tools.
  • Move laterally and distribute payloads with Cobalt Strike, SystemBC, PsExec, and Group Policy.
  • Split and compress stolen data with WinRAR and transfer it with WinSCP.
  • Encrypt Windows or ESXi workloads and pressure victims through email, phone calls, and threatened Tor publication.

Initial access and identity targets

Methods

  • Valid accounts reportedly purchased through criminal markets
  • RDP and VPN external remote services
  • FortiOS exploitation
  • Microsoft Exchange ProxyNotShell exploitation
  • SimpleHelp remote monitoring and management exploitation

Capabilities and evasion

Facts

  • Play recompiles the ransomware binary for individual attacks, reducing the value of payload-hash-only detection.
  • Windows encryption uses an AES-RSA hybrid design with intermittent encryption and appends .PLAY.
  • The ESXi variant powers off virtual machines, targets common VM disk and state files, and uses AES-256.
  • Grixba supports network and security-product discovery; Play has also used Cobalt Strike and SystemBC for command and control.
  • Observed defense-impairment tools include GMER, IOBit, PowerTool, and custom HRsword-related components.

Infrastructure patterns

Facts

  • Each victim receives a unique gmx.de or web.de email address for negotiation.
  • Non-paying victims are threatened with publication on a Tor-hosted data-leak site.
  • Plink has been used to establish persistent SSH tunnels.

Communication and pressure channels

Facts

  • Ransom notes initially direct victims to contact the group rather than stating the demand or payment instructions.

Channels

  • Victim-specific GMX or Web.de email
  • Telephone pressure
  • Tor data-leak site

Observed targeting

Targeting, not victimization. The regional and sector summary describes reported impact. The profile's live victim table contains leak-site claims and labels them separately from confirmed incidents.

Facts

  • Reported impact spans business, government, critical infrastructure, healthcare, and media organizations.
  • Observed regions include North America, South America, and Europe.

Defender guidance

Measures

  • Prioritize remediation of known exploited vulnerabilities in FortiOS, Microsoft Exchange, SimpleHelp, and other internet-facing services.
  • Require MFA for webmail, VPN, remote access, and privileged accounts.
  • Monitor for Grixba, AdFind, PsExec, Cobalt Strike, SystemBC, unusual Group Policy changes, and encoded PowerShell in context rather than treating every administration tool as malicious.
  • Alert on WinRAR staging followed by WinSCP transfers and on unexpected GMX or Web.de contact in ransomware notes.
  • Segment networks and isolate ESXi management interfaces, while maintaining tested offline backups and a recovery plan.

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
IdentityTracking identifier: G1040

Reviewed identity mapping approved on this date.

First listed
Victim claimSys-kool listed by Play

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimGrunthal Welding & Supplies listed by Play

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimRed Star Oil listed by Play

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimGT Distributors listed by Play

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimMEQ listed by Play

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimFiggins Family Wine Estates listed by Play

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimKRC Machine Tool Solutions listed by Play

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimMeteor Group listed by Play

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimBe Media listed by Play

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimLatoplast listed by Play

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimColtrane Systems listed by Play

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimBridgeport Capital Services listed by Play

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimSam Pack Auto Group listed by Play

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Cataloged
Indicator15 indicators cataloged

Types: sha1, sha256, tool.

Cataloged
IdentityAlias: Playcrypt

Reviewed identity mapping approved on this date.

First listed
Victim claimMIE Solutions listed by Play

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimRilpa Enterprises listed by Play

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimMarconi Industrial Services listed by Play

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimSignature Services listed by Play

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimGCATS Investments listed by Play

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimPlatinum Group listed by Play

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Claimed
Victim claimWoodhaven Association listed by Play

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimFirst Tek listed by Play

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimPreferred Financial Group listed by Play

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed

The interactive view includes 103 dated events with category filters and paging.

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

PlayCanonical Name
PlaycryptAlias
G1040Tracking Id

Loading CVEs, techniques, indicators, malware, victims, and activity...