Play ransomware, also known as PlayCrypt, is a double-extortion ransomware operation active since 2022 that targets Windows enterprise environments and has also been observed using a Linux/VMware ESXi locker derived from leaked Babuk source code. The group is tracked by some vendors as Balloonfly and has been associated with big-game-hunting intrusions as well as broader campaigns against small and medium-sized businesses. Victimology has included construction, manufacturing, professional services, healthcare, government, and other sectors, with notable activity in North America and earlier emphasis on Latin America, including Brazil.
Play operators commonly steal data before encryption and threaten public disclosure to pressure victims. Reported intrusion tradecraft includes exploitation of public-facing systems, especially Microsoft Exchange vulnerabilities such as CVE-2022-41080 and CVE-2022-41082, use of valid accounts including VPN access with legitimate credentials, and abuse of remote administration and post-exploitation tooling. Associated tooling and behaviors include SystemBC for persistent remote access, Cobalt Strike for post-compromise operations, AdFind and custom PowerShell for enumeration, WinPEAS for privilege escalation, RDP and SMB for lateral movement, and WinSCP for data exfiltration. The group has also used custom .NET tooling, including Grixba, to enumerate users, computers, software, services, security products, backup tools, and remote administration software across victim domains, and to clear logs on local and remote systems. Another observed custom tool copies files from Volume Shadow Copy Service snapshots to access locked files prior to encryption.
The ransomware itself uses a hybrid public-key and symmetric encryption scheme and employs anti-analysis and defense-evasion measures such as API hashing, encoded strings, obfuscated control flow, legitimate-looking names and locations, and log-clearing functionality in associated tooling. It enumerates local and network drives, skips selected files and directories to preserve system operability, writes metadata to encrypted files to track encryption state, and appends a characteristic encrypted-file extension. Play affiliates have also been linked to rapid deployment after compromise and to exploitation of Windows privilege-escalation vulnerabilities, including CLFS flaws used in broader ransomware ecosystem activity.
Play has been linked in reporting to ransomware-affiliate and infrastructure ecosystems that overlap with other major criminal operations, and bulletproof hosting providers have been identified as supporting infrastructure used by the group. Public reporting also notes possible ties or overlaps involving ShadowSyndicate and other access or affiliate ecosystems, but such relationships are best understood as ecosystem overlap rather than definitive unified attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The exploit (dubbed OWASSRF) allowed the attackers to bypass ProxyNotShell URL rewrite mitigations provided by Microsoft by likely targeting a critical flaw (CVE-2022-41080) that allows remote privilege escalation on Exchange servers. | Rackspace officials have revealed ... that the OWASSRF exploit was found on its network and Play ransomware was behind last month's ransomware attack.
They also managed to gain remote code execution on vulnerable servers by abusing CVE-2022-41082, the same bug exploited in ProxyNotShell attacks. | Rackspace officials have revealed ... that the OWASSRF exploit was found on its network and Play ransomware was behind last month's ransomware attack.
In November 2023, the Cybersecurity & Infrastructure Security Agency (CISA) published guidance for addressing vulnerability CVE-2023-4966, affecting Citrix NetScaler ADC and NetScaler Gateway. This vulnerability is also known as Citrix Bleed.
CVE-2025–29824: An unpatched Windows CLFS vulnerability exploited by Play ransomware, which is sometimes associated with broader ransomware ecosystem activities. While not directly attributed to Qilin, it highlights a pattern of exploiting critical OS vulnerabilities. | CVE-2025–29824: An unpatched Windows CLFS vulnerability exploited by Play ransomware, which is sometimes associated with broader ransomware ecosystem activities.
The American Hospital Association is warning hospitals and other healthcare sector organizations of rising double-extortion attack threats involving the Play ransomware group. | multiple ransomware groups, including initial access brokers with ties to Play ransomware operators, are also exploiting three vulnerabilities - CVE-2024-57727 - in remote monitoring and management tool SimpleHelp to conduct remote code execution at many U.S.-based entities
Play (AKA PlayCrypt) ransomware is a private ransomware operation that has been active since, at least, June 2022. The group operates in a double extortion method, where the victim data is stolen and leaked via a data leak site if the ransom demand is not paid.
Play (AKA PlayCrypt) ransomware is a private ransomware operation that has been active since, at least, June 2022. The group operates in a double extortion method, where the victim data is stolen and leaked via a data leak site if the ransom demand is not paid.
Play (AKA PlayCrypt) ransomware is a private ransomware operation that has been active since, at least, June 2022. The group operates in a double extortion method, where the victim data is stolen and leaked via a data leak site if the ransom demand is not paid.
Play (AKA PlayCrypt) ransomware is a private ransomware operation that has been active since, at least, June 2022. The group operates in a double extortion method, where the victim data is stolen and leaked via a data leak site if the ransom demand is not paid.
The following analytic identifies remote code execution (RCE) attempts targeting F5 BIG-IP, BIG-IQ, and Traffix SDC devices, specifically exploiting CVE-2020-5902.
10 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Play ransomware (also known as PlayCrypt), which is developed by a group Symantec tracks as Balloonfly, was launched in June 2022...
It has demonstrated the use of multiple top tier Ransomware-as-a-Service (RaaS) brands such as AlphaV/Blackcat, Lockbit, Play, Royal, Cl0p, Cactus and Ransomhub.
It has demonstrated the use of multiple top tier Ransomware-as-a-Service (RaaS) brands such as AlphaV/Blackcat, Lockbit, Play, Royal, Cl0p, Cactus and Ransomhub.
These RaaS programs include: Akira (Howling Scorpius) ALPHV (Ambitious Scorpius) DragonForce (Slippery Scorpius) Play (Fiddling Scorpius) Qilin (Spikey Scorpius) RansomHub (Spoiled Scorpius)
These RaaS programs include: Akira (Howling Scorpius) ALPHV (Ambitious Scorpius) DragonForce (Slippery Scorpius) Play (Fiddling Scorpius) Qilin (Spikey Scorpius) RansomHub (Spoiled Scorpius)
MyPillow, the US-based bedding brand founded by election conspiracy theorist Mike Lindell, has been listed by Play ransomware extortionists as an alleged victim.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
The Play binary was submitted to VirusTotal as part of an archive... containing various hack tools and utilities–including AnyDesk, NetCat, a privilege escalation batch file, and encoded PowerShell Empire scripts–which are associated with ransomware group techniques after achieving initial access.
There are a few other features such as DLL injection and networking that will not be covered in this analysis.
The report also describes payload hiding and execution techniques that make the disruption harder to catch. Sodinokibi encrypts embedded code until runtime, Magniber can run code inside another process, and Play uses legitimate-looking names and locations.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
their systems were encrypted in November... Almost the entire environment was encrypted.
51 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
113 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group noted for combining big-game hunting with SMB targeting through exposed or unpatched public-facing devices, mainly in North America.
Ransomware group noted for big-game hunting combined with SMB targeting through unpatched public-facing devices, concentrated in North America.
Ransomware family highlighted for low prevention rates; described as using legitimate-looking names and locations to hide activity before encryption.
A ransomware operation that remained active against industrial organizations but declined significantly in claim volume during Q2 2026.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.