THREAT_ACTOR · G1040
Play
Also known as: Play
Profile
Play is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a double-extortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.
MITRE ATT&CK ↗Techniques
26 ATT&CK techniques attributed to this actor.
T1003.001 LSASS MemoryT1016 System Network Configuration DiscoveryT1018 Remote System DiscoveryT1021.002 SMB/Windows Admin SharesT1027.010 Command ObfuscationT1030 Data Transfer Size LimitsT1048 Exfiltration Over Alternative ProtocolT1057 Process DiscoveryT1059.001 PowerShellT1059.003 Windows Command ShellT1070.004 File DeletionT1078 Valid AccountsT1078.002 Domain AccountsT1078.003 Local AccountsT1082 System Information DiscoveryT1083 File and Directory DiscoveryT1105 Ingress Tool TransferT1133 External Remote ServicesT1190 Exploit Public-Facing ApplicationT1518.001 Security Software DiscoveryT1560.001 Archive via UtilityT1587.001 MalwareT1588.002 ToolT1657 Financial TheftT1685 Disable or Modify ToolsT1685.005 Clear Windows Event Logs
Software
9 malware/tools attributed to this actor.
MimikatzPsExecCobalt StrikeNltestEmpireBloodHoundAdFindWevtutilPlaycrypt
Related corpus activity
9,607 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to Play.
| Indicator | Type | Family | Sev | Src |
|---|---|---|---|---|
| cve-2026-3102 | cve | — | 85 | 3 |
| cve-2026-1969 | cve | — | 85 | 1 |
| cve-2013-3307 | cve | — | 85 | 2 |
| cve-2014-2321 | cve | — | 85 | 1 |
| cve-2025-34117 | cve | — | 85 | 1 |
| cve-2021-29441 | cve | — | 85 | 1 |
| cve-2025-66478 | cve | — | 85 | 2 |
| cve-2021-27076 | cve | — | 85 | 1 |
| cve-2016-15047 | cve | — | 85 | 4 |
| cve-2018-8007 | cve | — | 85 | 1 |
| cve-2020-17456 | cve | — | 85 | 1 |
| cve-2025-2492 | cve | — | 85 | 2 |
| cve-2013-7471 | cve | — | 85 | 1 |
| cve-2021-25646 | cve | — | 85 | 1 |
| cve-2022-47945 | cve | — | 85 | 1 |
| cve-2016-5681 | cve | — | 85 | 2 |
| cve-2025-0921 | cve | — | 85 | 2 |
| cve-2026-22584 | cve | — | 85 | 2 |
| cve-2025-11837 | cve | — | 85 | 2 |
| cve-2025-68670 | cve | — | 85 | 2 |
| cve-2025-34054 | cve | — | 85 | 4 |
| cve-2024-1781 | cve | — | 85 | 1 |
| cve-2023-44976 | cve | ransomware | 85 | 2 |
| cve-2021-4045 | cve | — | 85 | 1 |
| cve-2020-22653 | cve | — | 85 | 2 |
| cve-2020-22658 | cve | — | 85 | 2 |
| cve-2026-4368 | cve | ransomware | 85 | 1 |
| cve-2017-18377 | cve | — | 85 | 1 |
| cve-2025-23304 | cve | — | 85 | 2 |
| cve-2026-0740 | cve | — | 85 | 1 |
Showing the top 30 by severity of 9,607.