Fiddling Scorpius is the name Palo Alto tracks for the threat group behind the Play ransomware operation, also known as PlayCrypt. Play has been active since at least June 2022 and uses double extortion, encrypting systems while exfiltrating data and threatening publication on its Tor-based leak site. Reporting cited in the content notes that some sources assess Play may have shifted toward a ransomware-as-a-service model in late 2023, although the group’s own leak site claims it remains a closed, private operation. Observed initial access methods associated with Play include valid account abuse, exploitation of public-facing applications, phishing and social engineering, and abuse of external remote services such as RDP and VPN. Specifically mentioned exploited technologies and vulnerabilities include Fortinet FortiOS SSL VPN, Microsoft Exchange, SimpleHelp, and Netlogon, including CVE-2018-13379, CVE-2020-12812, CVE-2024-57727, CVE-2022-41080, ProxyNotShell (CVE-2022-41040 and CVE-2022-41082), and ZeroLogon (CVE-2020-1472). The ransomware is written in C++ and includes anti-debugging and anti-analysis features such as garbage code and dead-end function returns. The content states that Play binaries were reported in 2025 to be recompiled for each attack, producing unique hashes per deployment. Operators have been observed hiding malicious files in the public music folder, creating new high-privilege accounts on victim machines, and using intermittent encryption. A Linux variant was reported in 2024 that only encrypts when executed in a VMware ESXi environment, indicating targeting of virtualized infrastructure. The content also notes reported associations involving Andariel, Balloonfly, Prolific Puma, QuadSwitcher, and Quantum, but does not establish all of these relationships as confirmed. It specifically states that Play and Quantum have been reported to partly share infrastructure. In event-related reporting, Fiddling Scorpius/Play ransomware distributors were linked to the compromise of the French Rugby Federation ahead of the 2023 Rugby World Cup, where systems were encrypted and personally identifiable information was exfiltrated.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat actor associated with Play ransomware distribution, impacting sports organizations through encryption and data theft.
Named as the group associated with the Play ransomware-as-a-service program that Muddled Libra has partnered with.
Activity cluster assessed/tracked as the operator behind Play ransomware operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.