Play ransomware, also referred to as PlayCrypt and play_ransomware, is a ransomware-as-a-service (RaaS) operation first spotted at the end of June 2022. It was named for the .play file extension and the word “PLAY” in its ransom note email. The malware is associated with double-extortion activity, with operators stealing data and threatening public release in addition to encrypting systems. The content describes Play as an active, high-volume ransomware threat that has impacted roughly 900 organizations by May 2025 according to cited FBI reporting, and as one of the top ransomware threats to critical infrastructure.
Play targets enterprise environments across multiple sectors, with explicit references to healthcare, manufacturing, and critical infrastructure victims. The American Hospital Association warned of rising double-extortion threats involving the Play group, and the content specifically notes impacts to hospitals and healthcare organizations. Publicly referenced victim activity includes the French Rugby Federation before the 2023 Rugby World Cup, Swiss government data exposure via supplier Xplain in 2023, Microchip Technology in 2024, and MyPillow in 2025. The victim tracking content shows a strong concentration in the United States, with additional victims across Canada, Europe, Asia-Pacific, Africa, Latin America, and the Caribbean.
The malware and its operators are described as using rapid post-compromise deployment compared with many peers. Reported tradecraft includes exploitation of public-facing applications, use of valid accounts, scheduled tasks, PowerShell, credential dumping including LSASS memory and NTDS theft, discovery of network services and security software, lateral movement via RDP and SMB/Windows Admin Shares, lateral tool transfer, data archiving, exfiltration over alternative protocols, remote access software for command and control, clearing Windows event logs, stopping services, inhibiting system recovery, disabling or modifying security tools, and encrypting data for impact. Huntress reporting cited in the content states that Play often deploys ransomware quickly and averages fewer than 10 actions before encryption in observed incidents.
Play has also been linked to defense evasion and recovery inhibition behaviors. The content states that PlayCrypt can use AlphaVSS to delete shadow copies, and ATT&CK-style mappings associate PlayCrypt with data encryption for impact, file and directory discovery, and inhibiting system recovery. Additional reporting says Play operators have used legitimate but vulnerable drivers to terminate EDR products. Splunk detection content also associates Play with use of wevtutil-style log disabling behavior.
The content further states that Play has exploited the Windows Common Log File System vulnerability CVE-2025-29824, and that multiple reports observed abuse of this flaw by Play-associated attackers before patching. Play is also listed among ransomware programs associated with Muddled Libra/Scattered Spider partnerships, though the content only states association rather than exclusive operational control.
A Linux/ESXi-focused variant is described in SentinelLABS reporting as the first known Linux version of Play ransomware. That sample referenced the .FinDom extension and the ransom email address findomswitch@fastmail.pw, artifacts associated with Play, and was assessed as Babuk-derived. The sample reportedly used the same file-searching functionality as baseline Babuk and Sosemanuk for encryption. The Play ESXi sample SHA1 is dc8b9bc46f1d23779d3835f2b3648c21f4cf6151, and the related archive SHA1 is 9290478cda302b9535702af3a1dada25818ad9ce. The archive reportedly contained AnyDesk, NetCat, a privilege-escalation batch file, and encoded PowerShell Empire scripts.
The content also states that Play uses intermittent encryption based on file size and encrypts chunks of 0x100000 bytes. Known artifacts and indicators mentioned in the content include the .play and .FinDom extensions, the ransom email findomswitch@fastmail.pw, email IOCs derdiarikucisv@gmx.de and raniyumiamrm@gmx.de, and a YARA artifact named Play.yar.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2025–29824: An unpatched Windows CLFS vulnerability exploited by Play ransomware, which is sometimes associated with broader ransomware ecosystem activities. While not directly attributed to Qilin, it highlights a pattern of exploiting critical OS vulnerabilities. | CVE-2025–29824: An unpatched Windows CLFS vulnerability exploited by Play ransomware, which is sometimes associated with broader ransomware ecosystem activities.
I conducted a retrospective study on the vulnerability CVE-2023-4966, commonly known as Citrix Bleed, which allows attackers to easily bypass authentication in Citrix's Citrix ADC and Citrix Gateway products, over the course of six months. Initially exploited by some attackers as a zero-day in August 2023, a patch was released on October 10, followed by the publication of a PoC in late October, after which various attackers exploited the vulnerability.
The American Hospital Association is warning hospitals and other healthcare sector organizations of rising double-extortion attack threats involving the Play ransomware group. | multiple ransomware groups, including initial access brokers with ties to Play ransomware operators, are also exploiting three vulnerabilities - CVE-2024-57727 - in remote monitoring and management tool SimpleHelp to conduct remote code execution at many U.S.-based entities
De plus, grâce à des liens d’infrastructure, l’ANSSI a pu rattacher au même MOA plusieurs exploitations de la vulnérabilité ProxyNotShell (CVE-2022-41080 et CVE-2022-41082) ayant mené au déploiement de Play.
De plus, grâce à des liens d’infrastructure, l’ANSSI a pu rattacher au même MOA plusieurs exploitations de la vulnérabilité ProxyNotShell (CVE-2022-41080 et CVE-2022-41082) ayant mené au déploiement de Play.
Play (AKA PlayCrypt) ransomware is a private ransomware operation that has been active since, at least, June 2022. The group operates in a double extortion method, where the victim data is stolen and leaked via a data leak site if the ransom demand is not paid.
Play (AKA PlayCrypt) ransomware is a private ransomware operation that has been active since, at least, June 2022. The group operates in a double extortion method, where the victim data is stolen and leaked via a data leak site if the ransom demand is not paid.
Play (AKA PlayCrypt) ransomware is a private ransomware operation that has been active since, at least, June 2022. The group operates in a double extortion method, where the victim data is stolen and leaked via a data leak site if the ransom demand is not paid.
Play (AKA PlayCrypt) ransomware is a private ransomware operation that has been active since, at least, June 2022. The group operates in a double extortion method, where the victim data is stolen and leaked via a data leak site if the ransom demand is not paid.
The following analytic identifies remote code execution (RCE) attempts targeting F5 BIG-IP, BIG-IQ, and Traffix SDC devices, specifically exploiting CVE-2020-5902.
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
These RaaS programs include: Akira (Howling Scorpius) ALPHV (Ambitious Scorpius) DragonForce (Slippery Scorpius) Play (Fiddling Scorpius) Qilin (Spikey Scorpius) RansomHub (Spoiled Scorpius)
These RaaS programs include: Akira (Howling Scorpius) ALPHV (Ambitious Scorpius) DragonForce (Slippery Scorpius) Play (Fiddling Scorpius) Qilin (Spikey Scorpius) RansomHub (Spoiled Scorpius)
MyPillow, the US-based bedding brand founded by election conspiracy theorist Mike Lindell, has been listed by Play ransomware extortionists as an alleged victim.
"...Super Quik had multiple internal files and surveillance video footage exposed by the Play ransomware operation, which claimed to have exfiltrated a 5.5 GB dataset from its systems."
Play (AKA PlayCrypt) ransomware is a private ransomware operation that has been active since, at least, June 2022. The group operates in a double extortion method, where the victim data is stolen and leaked via a data leak site if the ransom demand is not paid.
Play (AKA PlayCrypt) ransomware is a private ransomware operation that has been active since, at least, June 2022. The group operates in a double extortion method, where the victim data is stolen and leaked via a data leak site if the ransom demand is not paid.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
The Play binary was submitted to VirusTotal as part of an archive... containing various hack tools and utilities–including AnyDesk, NetCat, a privilege escalation batch file, and encoded PowerShell Empire scripts–which are associated with ransomware group techniques after achieving initial access.
Several entries describe malware examining running processes to determine if a debugger, sandbox, virtual environment, or analysis/security tools are present, such as AsyncRAT checking for a debugger, RogueRobin enumerating Wireshark and Sysinternals processes, and P8RAT checking for processes associated with virtual environments.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
Several entries describe malware examining running processes to determine if a debugger, sandbox, virtual environment, or analysis/security tools are present, such as AsyncRAT checking for a debugger, RogueRobin enumerating Wireshark and Sysinternals processes, and P8RAT checking for processes associated with virtual environments.
AG Scholtes — an organization based in NL — has fallen victim to a ransomware attack conducted by the group play.
Akira will delete system volume shadow copies via PowerShell commands. Avaddon deletes backups and shadow copies using native system tools. Babuk has the ability to delete shadow volumes using vssadmin.exe delete shadows /all /quiet. BlackCat can delete shadow copies using vssadmin.exe delete shadows /all /quiet and wmic.exe Shadowcopy Delete; it can also modify the boot loader using bcdedit /set {default} recoveryenabled No.
27 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
96 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware associated with cyber extortion and data-theft-based pressure tactics, including exfiltrating sensitive corporate and personal records and publishing stolen data via a dark-web leak portal.
Ransomware used against the French Rugby Federation, encrypting systems and exfiltrating PII ahead of the Rugby World Cup.
Ransomware/extortion malware used to breach organizations, steal data, threaten leaks, and disrupt business operations. The content notes it has targeted many organizations, including critical infrastructure, and has been used alongside tools that disable endpoint security.
Play is the named ransomware family repeatedly referenced throughout the content in connection with numerous victim listings and ATT&CK-style behaviors including credential dumping, lateral movement, exfiltration, and data encryption for impact.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.