Play, also known as PlayCrypt, is a Windows ransomware operation active since mid-2022 that conducts big-game-hunting and double-extortion attacks. Operators exfiltrate victim data before encrypting systems and threaten public disclosure if payment demands are not met. Symantec tracks the associated activity cluster as Balloonfly. Play has targeted organizations in Latin America, particularly Brazil, and later broadened operations against sectors including construction, professional services, manufacturing, healthcare, government, and telecommunications.
Play affiliates have obtained access through exploitation of vulnerable public-facing Microsoft Exchange servers, including an OWASSRF chain involving CVE-2022-41080 and CVE-2022-41082, as well as through VPN access using valid credentials. Post-compromise activity includes Active Directory and host reconnaissance, privilege-escalation tooling, remote-access utilities, PowerShell, RDP and SMB-based lateral movement, and data staging and exfiltration. Custom tooling such as Grixba inventories users, systems, services, installed software, security products, backup systems, and remote-administration tools; it can also clear local and remote event logs.
The ransomware is a 32-bit Windows executable that uses hybrid RSA-AES encryption, multithreaded local and network-drive traversal, selective or intermittent encryption for larger files, and metadata appended to encrypted files to record encryption state and protected key material. It incorporates encoded strings, API hashing, garbage instructions, and control-flow obfuscation to hinder analysis. Play has also used legitimate-looking executable names and locations to reduce detection. Associated operations have targeted backups and used tooling to access files in Volume Shadow Copy Service snapshots before encryption.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
On December 20, 2022, OWASSRF exploit was detected in the wild, used by the Play ransomware group using CVE-2022-41080 and CVE-2022-41082 to enable RCE through Outlook Web Access.
On December 20, 2022, OWASSRF exploit was detected in the wild, used by the Play ransomware group using CVE-2022-41080 and CVE-2022-41082 to enable RCE through Outlook Web Access.
In November 2023, the Cybersecurity & Infrastructure Security Agency (CISA) published guidance for addressing vulnerability CVE-2023-4966, affecting Citrix NetScaler ADC and NetScaler Gateway. This vulnerability is also known as Citrix Bleed.
CVE-2025–29824: An unpatched Windows CLFS vulnerability exploited by Play ransomware, which is sometimes associated with broader ransomware ecosystem activities. While not directly attributed to Qilin, it highlights a pattern of exploiting critical OS vulnerabilities. | CVE-2025–29824: An unpatched Windows CLFS vulnerability exploited by Play ransomware, which is sometimes associated with broader ransomware ecosystem activities.
The American Hospital Association is warning hospitals and other healthcare sector organizations of rising double-extortion attack threats involving the Play ransomware group. | multiple ransomware groups, including initial access brokers with ties to Play ransomware operators, are also exploiting three vulnerabilities - CVE-2024-57727 - in remote monitoring and management tool SimpleHelp to conduct remote code execution at many U.S.-based entities
Play (AKA PlayCrypt) ransomware is a private ransomware operation that has been active since, at least, June 2022. The group operates in a double extortion method, where the victim data is stolen and leaked via a data leak site if the ransom demand is not paid.
Play (AKA PlayCrypt) ransomware is a private ransomware operation that has been active since, at least, June 2022. The group operates in a double extortion method, where the victim data is stolen and leaked via a data leak site if the ransom demand is not paid.
Play (AKA PlayCrypt) ransomware is a private ransomware operation that has been active since, at least, June 2022. The group operates in a double extortion method, where the victim data is stolen and leaked via a data leak site if the ransom demand is not paid.
Play (AKA PlayCrypt) ransomware is a private ransomware operation that has been active since, at least, June 2022. The group operates in a double extortion method, where the victim data is stolen and leaked via a data leak site if the ransom demand is not paid.
The following analytic identifies remote code execution (RCE) attempts targeting F5 BIG-IP, BIG-IQ, and Traffix SDC devices, specifically exploiting CVE-2020-5902.
10 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
On December 20, 2022, OWASSRF exploit was detected in the wild, used by the Play ransomware group using CVE-2022-41080 and CVE-2022-41082 to enable RCE through Outlook Web Access.
It has demonstrated the use of multiple top tier Ransomware-as-a-Service (RaaS) brands such as AlphaV/Blackcat, Lockbit, Play, Royal, Cl0p, Cactus and Ransomhub.
It has demonstrated the use of multiple top tier Ransomware-as-a-Service (RaaS) brands such as AlphaV/Blackcat, Lockbit, Play, Royal, Cl0p, Cactus and Ransomhub.
These RaaS programs include: Akira (Howling Scorpius) ALPHV (Ambitious Scorpius) DragonForce (Slippery Scorpius) Play (Fiddling Scorpius) Qilin (Spikey Scorpius) RansomHub (Spoiled Scorpius)
These RaaS programs include: Akira (Howling Scorpius) ALPHV (Ambitious Scorpius) DragonForce (Slippery Scorpius) Play (Fiddling Scorpius) Qilin (Spikey Scorpius) RansomHub (Spoiled Scorpius)
MyPillow, the US-based bedding brand founded by election conspiracy theorist Mike Lindell, has been listed by Play ransomware extortionists as an alleged victim.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
The Play binary was submitted to VirusTotal as part of an archive... containing various hack tools and utilities–including AnyDesk, NetCat, a privilege escalation batch file, and encoded PowerShell Empire scripts–which are associated with ransomware group techniques after achieving initial access.
There are a few other features such as DLL injection and networking that will not be covered in this analysis.
The report also describes payload hiding and execution techniques that make the disruption harder to catch. Sodinokibi encrypts embedded code until runtime, Magniber can run code inside another process, and Play uses legitimate-looking names and locations.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
55 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
116 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as one of the five most common ransomware-as-a-service brands in Sophos's ransomware observations.
Ransomware group mentioned as an ongoing active extortion operation continuing to name new victims.
Ransomware group noted for combining big-game hunting with SMB targeting through exposed or unpatched public-facing devices, mainly in North America.
Ransomware group noted for big-game hunting combined with SMB targeting through unpatched public-facing devices, concentrated in North America.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.