The Play ransomware group, also tracked as PlayCrypt and attributed by Symantec to Balloonfly, has conducted double-extortion intrusions since 2022 while refining both its initial access and post-compromise tradecraft. Symantec reported the group exploited Microsoft Exchange flaws CVE-2022-41080 and CVE-2022-41082, then used newly observed custom .NET utilities to accelerate victim profiling and data access before encryption. One tool, Grixba, surveys domain users, computers, software, services, security products, backup platforms, and remote administration tools, and can also clear logs on local and remote systems; another uses the AlphaVSS library to copy files from Volume Shadow Copy Service snapshots, including files normally locked by the operating system.
Reverse-engineering of the Play encryptor shows a ransomware family built for enterprise attacks, using a hybrid RSA-AES scheme, heavy obfuscation, API hashing, and anti-analysis techniques. The malware has been linked with tools and access methods including SystemBC RAT, Cobalt Strike, AdFind, WinPEAS, WinSCP, RDP, and SMB, and it enumerates local and network drives, skips selected files and directories, encrypts files in size-based chunks, appends the .PLAY extension, and drops a ReadMe.txt ransom note. Researchers also noted a coding flaw that can cause files to be renamed even when encryption does not complete successfully, underscoring both the malware’s sophistication and its ongoing evolution.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
Orange Cyberdefense reported handling three recent PLAY ransomware cases and linked them with two additional France-related cases based on overlapping IoCs and TTPs. The responders assessed that the activity may be tied to a distinct PLAY affiliate, possibly one specializing in Europe, and noted SystemBC recovery in related cases.
A reverse-engineering analysis detailed Play's anti-analysis techniques, hybrid RSA-AES encryption, file traversal and chunked encryption behavior, and noted a bug where files may still be renamed even if encryption fails.
The first public case of Play ransomware was announced in mid-August 2022, when Argentina’s Judiciary of Córdoba was reported as a victim.
Reverse-engineering analysis stated that Play ransomware had been active since at least mid-July 2022, using big-game-hunting tactics and associated tooling such as SystemBC RAT, Cobalt Strike, AdFind, WinPEAS, WinSCP, RDP, and SMB.
Symantec reported that the Play ransomware group, also known as PlayCrypt, launched in June 2022 and began conducting double-extortion attacks.
Symantec disclosed that Play operators were using two custom .NET tools in intrusions: Grixba for broad network and software enumeration and log clearing, and another tool using AlphaVSS to copy files from Volume Shadow Copy snapshots before encryption.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 17 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
symantec-enterprise-blogs.security.com
Open sourceorangecyberdefense.com
Open sourcechuongdong.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.