Trend Micro reported that the Play ransomware operation uses an intrusion and extortion playbook that closely resembles activity previously associated with Hive and Nokoyawa, suggesting overlap in tooling, tradecraft, or operator relationships. The group was observed relying on hands-on-keyboard techniques after initial access, moving laterally through victim environments and deploying ransomware in a manner consistent with established big-game hunting operations.
The research indicates that Play’s methods align with a broader ransomware ecosystem in which affiliates or closely linked actors reuse proven attack chains, making attribution and defense more difficult. For defenders, the overlap highlights the need to monitor for shared behaviors across ransomware families rather than relying only on malware names, especially around post-compromise lateral movement, privilege escalation, and data-extortion activity.

TTPs, infrastructure, and targeting history in one profile.
1 event from the most recent confirmed update back to the earliest known activity.
Trend Micro published research analyzing the Play ransomware group's attack playbook and reported similarities to the tactics, techniques, and procedures associated with Hive and Nokoyawa, suggesting an affiliation or overlap in operations.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.