Play, also known as Playcrypt, is a ransomware family and associated extortion operation active since at least June 2022. It encrypts enterprise systems and supports double-extortion campaigns in which attackers steal sensitive data before encryption and threaten public disclosure to pressure victims into paying. Play uses intermittent encryption, and its deployments include Windows payloads and a Linux variant targeting VMware ESXi environments. Victims span multiple regions and sectors, including healthcare, critical infrastructure, manufacturing, education, financial services, hospitality, and government.
Play intrusions have used compromised VPN and RDP accounts and exploitation of internet-facing systems. Documented access methods include FortiOS vulnerabilities and Microsoft Exchange exploitation, including the OWASSRF chain combining CVE-2022-41080 and CVE-2022-41082. OWASSRF enables remote code execution through Outlook Web Access while bypassing URL rewrite mitigations introduced for ProxyNotShell. Play operators also abuse legitimate remote-access and administrative software, including ScreenConnect and SimpleHelp.
Observed post-compromise activity includes credential extraction with Mimikatz, Active Directory and virtualization-infrastructure reconnaissance, and lateral movement through RDP, WMI, PsExec, and SMB administrative shares. Operators manually identify valuable documents, stage stolen data in WinRAR archives, and exfiltrate it using WinSCP or FTP. SystemBC has been used to maintain access and tunnel command-and-control traffic. Before deploying ransomware, attackers have disabled endpoint protection and Windows firewall controls, configured antivirus exclusions, cleared security logs, and deleted shadow copies to impede recovery. Payloads have been distributed across domain controllers, file servers, database servers, virtualization hosts, and workstations. Play deployments have also been associated with intrusions involving the North Korean threat actor Andariel.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
“Path Traversal: This secondary vulnerability provides attackers with a method to access unauthorized files, further compromising the integrity of the system. (CVE-2024-1708)”
Microsoft says Cuba ransomware threat actors are hacking Microsoft Exchange servers unpatched against a critical server-side request forgery vulnerability also exploited in Play ransomware attacks. Rackspace confirmed that Play ransomware used an exploit dubbed OWASSRF targeting CVE-2022-41080 after bypassing ProxyNotShell URL rewrite mitigations.
“Authentication Bypass ... allows nefarious actors to generate their own administrative user on the platform, granting them complete control over the platform. (CVE-2024-1709)”
Another infection vector used by the group is the exploitation of public-facing applications, particularly through ... Microsoft Exchange (CVE-2022-41040 and CVE-2022-41082, also known as ProxyNotShell) vulnerabilities. | The Play ransomware group (also known as Playcrypt) has been active since at least June 2022.
Another infection vector used by the group is the exploitation of public-facing applications, particularly through ... Microsoft Exchange (CVE-2022-41040 and CVE-2022-41082, also known as ProxyNotShell) vulnerabilities. | The Play ransomware group (also known as Playcrypt) has been active since at least June 2022.
Another infection vector used by the group is the exploitation of public-facing applications, particularly through known FortiOS (CVE-2018-13379 and CVE-2020-12812) ... vulnerabilities. | The Play ransomware group (also known as Playcrypt) has been active since at least June 2022.
Another infection vector used by the group is the exploitation of public-facing applications, particularly through known FortiOS (CVE-2018-13379 and CVE-2020-12812) ... vulnerabilities. | The Play ransomware group (also known as Playcrypt) has been active since at least June 2022.
In November 2023, the Cybersecurity & Infrastructure Security Agency (CISA) published guidance for addressing vulnerability CVE-2023-4966, affecting Citrix NetScaler ADC and NetScaler Gateway. This vulnerability is also known as Citrix Bleed.
CVE-2025–29824: An unpatched Windows CLFS vulnerability exploited by Play ransomware, which is sometimes associated with broader ransomware ecosystem activities. While not directly attributed to Qilin, it highlights a pattern of exploiting critical OS vulnerabilities. | CVE-2025–29824: An unpatched Windows CLFS vulnerability exploited by Play ransomware, which is sometimes associated with broader ransomware ecosystem activities.
The American Hospital Association is warning hospitals and other healthcare sector organizations of rising double-extortion attack threats involving the Play ransomware group. | multiple ransomware groups, including initial access brokers with ties to Play ransomware operators, are also exploiting three vulnerabilities - CVE-2024-57727 - in remote monitoring and management tool SimpleHelp to conduct remote code execution at many U.S.-based entities
Play (AKA PlayCrypt) ransomware is a private ransomware operation that has been active since, at least, June 2022. The group operates in a double extortion method, where the victim data is stolen and leaked via a data leak site if the ransom demand is not paid.
The following analytic identifies remote code execution (RCE) attempts targeting F5 BIG-IP, BIG-IQ, and Traffix SDC devices, specifically exploiting CVE-2020-5902.
11 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Play ransomware group (also known as Playcrypt) has been active since at least June 2022.
Early examples include North Korean APTs “Andariel” and “Moonstone Sleet” deploying “Play” ransomware and “Qilin,” respectively.
ShadowSyndicate "had been associated with the ALPHV/BlackCat, Cl0p, Royal, Play, Cactus, Nokoyawa, and Quantum ransomware operations."
Two separate PlayCrypt intrusions used RDP with compromised administrator credentials, WinRAR staging using '-ep1 -scul -r0', WinSCP exfiltration, and—in the second intrusion—ransomware deployment from C:\Users\Public\Music\ across 15+ hosts.
Two separate PlayCrypt intrusions used RDP with compromised administrator credentials, WinRAR staging using '-ep1 -scul -r0', WinSCP exfiltration, and—in the second intrusion—ransomware deployment from C:\Users\Public\Music\ across 15+ hosts.
These RaaS programs include: Akira (Howling Scorpius) ALPHV (Ambitious Scorpius) DragonForce (Slippery Scorpius) Play (Fiddling Scorpius) Qilin (Spikey Scorpius) RansomHub (Spoiled Scorpius)
16 distinct techniques documented for this family, organized by ATT&CK tactic.
The report also describes payload hiding and execution techniques that make the disruption harder to catch. Sodinokibi encrypts embedded code until runtime, Magniber can run code inside another process, and Play uses legitimate-looking names and locations.
56 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
134 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware mentioned as background context for prior attacks involving SimpleHelp. No ransomware-specific behavior or distribution details are provided.
Ransomware family mentioned only in a headline alleging exposure of stolen Super Quik data.
RaaS ransomware that uses intermittent encryption, targets managed service providers and security-vendor access, and includes a Linux variant targeting VMware ESXi.
Ransomware-as-a-service used by the North Korean-linked Andariel group in 2024.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.