Play, also known as Playcrypt and Balloonfly, is a financially motivated ransomware operation active since at least June 2022. It primarily operates as a closed, internally controlled intrusion and ransomware crew rather than an openly recruited ransomware-as-a-service program. Its country of origin is not established. Play targets organizations across North America, South America, and Europe, including healthcare, manufacturing, technology, financial services, hospitality, education, and government entities. Known victims include Rackspace, Germany’s H-Hotels hotel chain, the Belgian city of Antwerp, and Argentina’s Judiciary of Córdoba. Play conducts double extortion, stealing sensitive information before encrypting systems and threatening publication on its dedicated leak site. Its operators have also telephoned victims to encourage payment. Initial access methods include abuse of valid VPN and RDP accounts and exploitation of internet-facing systems. Observed exploitation includes FortiOS vulnerabilities CVE-2018-13379 and CVE-2020-12812, Microsoft Exchange ProxyNotShell vulnerabilities CVE-2022-41040 and CVE-2022-41082, and the OWASSRF exploitation chain involving CVE-2022-41080, which bypassed ProxyNotShell URL rewrite mitigations. Play’s intrusion tooling includes SystemBC for command and control and sustained access, Mimikatz for credential theft, and PsExec for lateral movement and ransomware distribution. Operators enumerate virtualization infrastructure and network shares, archive sensitive data with WinRAR, and transfer stolen information using WinSCP. Defense-evasion behavior includes clearing Windows Security logs and disabling endpoint protection. In one investigated intrusion, Play removed SentinelOne using the victim’s legitimate SentinelCleaner utility; separate attacks associated with Play have involved the EDRKillShifter vulnerable-driver tool. These activities support coordinated data theft and widespread encryption across compromised environments.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
45 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 malware families attributed to this actor across reporting.
8 additional families tracked in Mallory.
18 CVEs this actor has used in observed campaigns. 18 of them exploited in the wild.
The Common Log File System (CLFS) 0-day vulnerability CVE-2025–29824 was confirmed to have been exploited by attackers associated with PLAY and Storm-2460, and according to Symantec, the vulnerability may have already fallen into the hands of multiple attackers and been exploited before it was patched.
Another infection vector used by the group is the exploitation of public-facing applications, particularly through ... Microsoft Exchange (CVE-2022-41040 and CVE-2022-41082, also known as ProxyNotShell) vulnerabilities.
Another infection vector used by the group is the exploitation of public-facing applications, particularly through ... Microsoft Exchange (CVE-2022-41040 and CVE-2022-41082, also known as ProxyNotShell) vulnerabilities.
Another infection vector used by the group is the exploitation of public-facing applications, particularly through known FortiOS (CVE-2018-13379 and CVE-2020-12812) ... vulnerabilities.
Another infection vector used by the group is the exploitation of public-facing applications, particularly through known FortiOS (CVE-2018-13379 and CVE-2020-12812) ... vulnerabilities.
13 more CVEs tied to this actor tracked in Mallory.
82 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Reportedly conducted a ransomware attack against Silicon Valley Glass, a US organization identified as operating in manufacturing. The incident was discovered on October 4, 2026, at 19:36 UTC. The content provides no technical details or independent attribution evidence.
The content attributes a ransomware attack against US-based Bold Spring Nursery to Play. It lists the breach as occurring on October 4, 2026, at 19:36 UTC, with discovery one minute later. No technical evidence or attack-chain details are provided.
Play lists Bold Spring Nursery, a United States organization, as a victim, with a discovery date of October 4, 2026. The post provides no stolen-data details, proof of compromise, ransom amount, or deadline.
Play lists Silicon Valley Glass, a US manufacturing/engineering organization, as a victim, with a discovery date of October 4, 2026. The post provides no stolen-data details, proof of compromise, ransom amount, or deadline.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.