Play/PlayCrypt ransomware operators have used a repeatable double-extortion workflow beginning with compromised administrator credentials and RDP access. In two examined intrusions, the actors manually identified valuable data, archived it with WinRAR using the distinctive -ep1 -scul -r0 options, and exfiltrated it through WinSCP. One operation was disrupted before encryption but continued data theft after defenders disabled an account; another reached encryption on more than 15 systems within roughly six hours, using PsExec to deploy distinct ransomware payloads from C:\Users\Public\Music\, disabling Windows protections, and deleting shadow copies.
The group, active since 2022 and responsible for roughly 900 known victim entities as of May 2025, also gains entry through exposed applications, including FortiOS, Microsoft Exchange ProxyNotShell, and activity associated with SimpleHelp CVE-2024-57727. Its tooling includes Grixba for domain-wide discovery and inventory of security, backup, and remote-management products, plus a custom VSS utility that copies locked files from shadow snapshots before encryption. Defenders should prioritize MFA and rapid remediation of internet-facing vulnerabilities, while monitoring for the WinRAR command-line pattern, WinSCP transfers, Defender exclusions, random service creation, PsExec activity, and executable writes under the Public Music directory; offline immutable backups and network segmentation remain essential to limit impact.

TTPs, infrastructure, and targeting history in one profile.
20 events from the most recent confirmed update back to the earliest known activity.
The FBI, CISA, and ASD's ACSC updated their Play ransomware advisory with newly observed tactics, techniques, and procedures and refreshed indicators based on FBI investigations through January 2025.
As of May, the FBI was aware of approximately 900 entities allegedly exploited by Play ransomware actors.
Multiple ransomware groups, including initial-access brokers linked to Play operators, exploited SimpleHelp CVE-2024-57727 after its public disclosure to gain remote code execution through PowerShell.
At the end of August, QuadSwitcher compromised a Western European technology company that was later posted on Medusa's leak site. The actors downloaded PuTTY and MeshAgent with certutil.exe and used Process Explorer and EDRKillShifter.
QuadSwitcher compromised a governmental institution in North America, using PuTTY, Rclone, AnyDesk, EDRKillShifter, and TDSSKiller during the intrusion.
In early August, QuadSwitcher compromised a North American manufacturing company and ultimately deployed the Play encryptor after using SystemBC, EDRKillShifter, and WKTools.
At the end of July, QuadSwitcher compromised a North American legal-sector organization later listed on BianLian's leak site. The intrusion used tools including ntdsutil, AnyDesk, ScreenConnect, EDRKillShifter, WKTools, SystemBC, and a BianLian backdoor.
The affiliate cluster ESET tracks as QuadSwitcher deployed the RansomHub encryptor and EDRKillShifter against a Western European manufacturing company and a Central European automotive company.
RansomHub changed its affiliate rules to strictly require a US$5,000 deposit following an alleged breach by security researchers.
RansomHub announced an improved version of EDRKillShifter; ESET subsequently observed affiliates deploying it four days later.
RansomHub introduced its custom EDR-killing tool, EDRKillShifter, to affiliates through its web panel. The tool abused vulnerable drivers through BYOVD techniques and protected key execution logic with a password.
RansomHub announced its first victim, marking the operation's public emergence shortly before the announcement of Operation Cronos.
RansomHub advertised its RaaS operation on the Russian-speaking RAMP forum, offering affiliates direct ransom payments, a 90% revenue share, and Windows, Linux, and ESXi encryptors.
The FBI, CISA, and ASD's ACSC issued the original joint #StopRansomware advisory covering Play ransomware activity, its tactics, and indicators.
Another Play ransomware incident was observed in Australia.
Australian authorities observed their first Play ransomware incident.
Play ransomware, also known as PlayCrypt, was launched and began impacting businesses and critical infrastructure in the Americas and Europe. The group initially focused on Latin American organizations, particularly Brazil, before broadening its targeting.
In a separate Play intrusion, operators exfiltrated about 2.8 GB to attacker-controlled infrastructure, disabled Windows protections, deleted shadow copies, and used PsExec to deploy unique ransomware binaries from C:\Users\Public\Music\ to more than 15 hosts in approximately six hours.
In one Play intrusion, operators used compromised administrator credentials and RDP, staged data with WinRAR, and exfiltrated it with WinSCP. Defenders disabled one compromised account, but the actors switched to a backup administrator account and continued exfiltration; no ransomware encryption was observed.
Symantec reported Play intrusions using Grixba for domain-wide discovery and security-software enumeration, alongside a custom .NET utility that copies files from VSS snapshots before encryption, including files normally locked by the operating system.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 18 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
6 references tracked. Mallory keeps watching after this page renders.
shroudcloud.io
Open sourcecisa.gov
Open sourcewelivesecurity.com
Open sourcetrendmicro.com
Open sourceunit42.paloaltonetworks.com
Open sourcesecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.