Play, also known as PlayCrypt and tracked by Palo Alto Networks as Fiddling Scorpius, is a ransomware operation active since at least mid-2022. It is primarily associated with financially motivated cybercrime and is known for double-extortion attacks that combine data theft with system encryption and leak-site pressure. Reporting has described Play both as a closed private operation and, in some cases, as behaving similarly to a ransomware-as-a-service ecosystem, but the strongest supported characterization is that it is the threat group behind the Play ransomware operation. Play intrusion activity has been associated with multiple initial-access routes, including abuse of valid accounts, exploitation of public-facing applications, phishing and other social-engineering methods, and abuse of external remote services such as VPN and RDP. Public reporting has linked exploitation in Play incidents to FortiOS SSL VPN, Microsoft Exchange, SimpleHelp, and Netlogon weaknesses. After access, Play operators have been observed creating high-privilege accounts, conducting Active Directory discovery, using common post-exploitation and remote administration tooling, and moving laterally through victim environments while evading defenses. The ransomware itself is written in C++ and incorporates anti-debugging and anti-analysis measures. Reporting in 2025 indicated that the payload was recompiled per victim, producing unique samples for each deployment. A Linux variant has also been reported, including one tailored to encrypt files in VMware ESXi environments, indicating capability against virtualized infrastructure as well as Windows networks. Play has been linked to data exfiltration prior to encryption and to publication threats through its leak site, consistent with double extortion. Victimology spans multiple sectors, and the operation has been cited in connection with attacks affecting major-event and hospitality-adjacent organizations. One specifically reported case involved the French Rugby Federation ahead of the 2023 Rugby World Cup, where systems were encrypted and personally identifiable information was exfiltrated. Various public sources have discussed possible associations between Play and other clusters or ecosystems, including Quantum, Prolific Puma, Balloonfly, QuadSwitcher, and Andariel, but such relationships are not uniformly confirmed and should be treated cautiously. The most established naming in this context is Play or PlayCrypt, with Fiddling Scorpius used as a vendor tracking name for the group behind the operation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat actor associated with Play ransomware distribution, impacting sports organizations through encryption and data theft.
Named as the group associated with the Play ransomware-as-a-service program that Muddled Libra has partnered with.
Activity cluster assessed/tracked as the operator behind Play ransomware operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.