Ransomware Group intelligence
Play
ActiveTrack Play with 1349 published victims and 5 known leak locations in a single intelligence view.
Overview
Play is tracked by Breach House as a ransomware group with 1349 published victims.
United States is currently the most targeted country in this dataset.
5 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (5)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 5 | Onion service | Up checked 1h ago | ipi4tiumgzjsym6pyuzrfqrtwskokxokqannmd6sa24shvr7x5kxdvqd.onion |
| Leak location 4 | Onion service | Up checked 1h ago | j75o7xvvsm4lpsjhkjvb4wl2q6ajegvabe6oswthuaubbykk4xkzgpid.onion |
| Leak location 1 | Onion service | Down checked 1h ago | mbrlkbtq5jonaqkurjwmxftytyn2ethqvbxfu4rgjbkkknndqwae6byd.onion |
| Leak location 2 | Onion service | Down checked 1h ago | k7kg3jqxang3wh7hnmaiokchk7qoebupfgoik6rha6mjpzwupwtj25yd.onion |
| Leak location 3 | Onion service | Down checked 1h ago | mbrlkbtq5jonaqkurjwmxftytyn2ethqvbxfu4rgjbkkknndqwae6byd.onion |
Top Activity Sectors (17)
- Public Sector 588
- Not identified 227
- Services 77
- Manufacturing / Engineering 72
- Communication / Marketing 66
- IT 63
- Finance / Legal / Insurance 54
- Construction / Real Estate 42
- Energy 21
- Agriculture / Food 19
- Transportation / Travel / Logistics 19
- Hospitality / Food & Beverage / Tourism 16
- Retail / E-commerce 15
- Telecommunications 11
- NGOs / Associations 6
- Healthcare / Pharma 4
- Education 2
Typical Attacks (28)
▼How Play typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via Play, Playcrypt.
-
T1587.001 Malware Resource Development
What they do: Play developed and employ Playcrypt ransomware.
What that means: Adversaries may develop malware and malware components that can be used during targeting.
-
T1588.002 Tool Resource Development
What they do: Play has used multiple tools for discovery and defense evasion purposes on compromised hosts.
What that means: Adversaries may buy, steal, or download software tools that can be used during targeting.
-
What they do: Play has used valid VPN accounts to achieve initial access.
What that means: Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
What they do: Play has used valid domain accounts for access.
What that means: Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
What they do: Play has used valid local accounts to gain initial access.
What that means: Adversaries may obtain and abuse credentials of a local account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
What they do: Play has used Remote Desktop Protocol (RDP) and Virtual Private Networks (VPN) for initial access.
What that means: Adversaries may leverage external-facing remote services to initially access and/or persist within a network.
-
T1190 Exploit Public-Facing Application Initial Access
What they do: Play has exploited known vulnerabilities for initial access including CVE-2018-13379 and CVE-2020-12812 in FortiOS and CVE-2022-41082 and CVE-2022-41040 ("ProxyNotShell") in Microsoft Exchange.
What that means: Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
-
T1059.001 PowerShell Execution
What they do: Play has used Base64-encoded PowerShell scripts to disable Microsoft Defender.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1059.003 Windows Command Shell Execution
What they do: Play has used a batch script to remove indicators of its presence on compromised hosts.
What that means: Adversaries may abuse the Windows command shell for execution.
-
T1027.010 Command Obfuscation Stealth
What they do: Play has used Base64-encoded PowerShell scripts for post exploit activities on compromised hosts.
What that means: Adversaries may obfuscate content during command execution to impede detection.
-
T1070.004 File Deletion Stealth
What they do: Play has used tools including Wevtutil to remove malicious files from compromised hosts.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: Play has used tools including GMER, IOBit, and PowerTool to disable antivirus software.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1685.005 Clear Windows Event Logs Defense Impairment
What they do: Play has used tools to remove log files on targeted systems.
What that means: Adversaries may clear Windows Event Logs to hide the activity of an intrusion.
-
T1003.001 LSASS Memory Credential Access
What they do: Play has used Mimikatz and the Windows Task Manager to dump LSASS process memory.
What that means: Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).
-
T1016 System Network Configuration Discovery Discovery
What they do: Play has used the information-stealing tool Grixba to enumerate network information.
What that means: Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems.
-
T1018 Remote System Discovery Discovery
What they do: Play has used tools such as AdFind, Nltest, and BloodHound to enumerate shares and hostnames on compromised networks.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1057 Process Discovery Discovery
What they do: Play has used the information stealer Grixba to check for a list of security processes.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1082 System Information Discovery Discovery
What they do: Play has leveraged tools to enumerate system information.
What that means: An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture.
-
T1083 File and Directory Discovery Discovery
What they do: Play has used the Grixba information stealer to list security files and processes.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1518.001 Security Software Discovery Discovery
What they do: Play has used the information-stealing tool Grixba to scan for anti-virus software.
What that means: Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: Play has used Cobalt Strike to move laterally via SMB.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1560.001 Archive via Utility Collection
What they do: Play has used WinRAR to compress files prior to exfiltration.
What that means: Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration.
-
T1105 Ingress Tool Transfer Command and Control
What they do: Play has used Cobalt Strike to download files to compromised machines.
What that means: Adversaries may transfer tools or other files from an external system into a compromised environment.
-
T1030 Data Transfer Size Limits Exfiltration
What they do: Play has split victims' files into chunks for exfiltration.
What that means: An adversary may exfiltrate data in fixed size chunks instead of whole files or limit packet sizes below certain thresholds.
-
T1048 Exfiltration Over Alternative Protocol Exfiltration
What they do: Play has used WinSCP to exfiltrate data to actor-controlled accounts.
What that means: Adversaries may steal data by exfiltrating it over a different protocol than that of the existing command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: Playcrypt encrypts files on targeted hosts with an AES-RSA hybrid encryption, encrypting every other file portion of 0x100000 bytes.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: Playcrypt can use AlphaVSS to delete shadow copies.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
-
T1657 Financial Theft Impact
What they do: Play demands ransom payments from victims to unencrypt filesystems and to not publish sensitive data exfiltrated from victim networks.
What that means: Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims.
Tools Observed (11)
▼Software Play has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Defense evasion
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Networking & tunnelling
Offensive security tooling
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (3)
▼The note this group leaves on a compromised machine. Click a filename to read it.
ReadMe2.txt
Your network has been encrypted. Your private, personal, corporate, confidential data has been stolen. If you do not resolve the issue, your data will be published on our leak portal. News portal, tor network links: ipi4tiumgzjsym6pyuzrfqrtwskokxokqannmd6sa24shvr7x5kxdvqd.onion j75o7xvvsm4lpsjhkjvb4wl2q6ajegvabe6oswthuaubbykk4xkzgpid.onion contact email: [email protected] PLAY Ransomware Team
ReadMe.txt
PLAY news portal, tor network links: mbrlkbtq5jonaqkurjwmxftytyn2ethqvbxfu4rgjbkkknndqwae6byd.onion k7kg3jqxang3wh7hnmaiokchk7qoebupfgoik6rha6mjpzwupwtj25yd.onion [email protected]
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (1349)
Search, filter and paginate the victim timeline for Play. Showing 1201–1300 of 1349.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Summit Hut id6982 View details | United States | Public Sector | — | |
|
Arizona, United States |
|||||
| Ransomware | OMNIPOL id6980 View details | Czechia | Public Sector | — | |
|
Czech Republic |
|||||
| Ransomware | Hi-tec, Batra Group id6979 View details | United Kingdom | Services | — | |
|
United Kingdom |
|||||
| Ransomware | Barentz North America id6978 View details | United States | Hospitality / Food & Beverage / Tourism | — | |
|
Ohio, United States |
|||||
| Ransomware | PWI Engineering id6977 View details | United States | Manufacturing / Engineering | — | |
|
New Jersey, United States |
|||||
| Ransomware | Federation Francaise de Rugby id6976 View details | France | NGOs / Associations | — | |
|
France |
|||||
| Ransomware | Luís Simoes id6975 View details | Portugal | Other | — | |
|
Portugal |
|||||
| Ransomware | Allpro Consulting Group id6974 View details | United States | Communication / Marketing | — | |
|
Texas, United States |
|||||
| Ransomware | Lorclon id6973 View details | United Kingdom | Other | — | |
|
United Kingdom |
|||||
| Ransomware | wolfs block management limited id6968 View details | United Kingdom | Services | — | |
|
United Kingdom |
|||||
| Ransomware | Globalcaja id6709 View details | Spain | Services | ||
|
Spain |
|||||
| Ransomware | Fortress Paper id6708 View details | Canada | Other | ||
|
Canada |
|||||
| Ransomware | Unico Data,INSYS Industriesysteme,PathA Suisse,PB Swiss Tools,Boess Gruppe id6707 View details | Switzerland | Other | ||
|
Switzerland |
|||||
| Ransomware | Alberta Newsprint id6706 View details | Canada | Communication / Marketing | ||
|
Canada |
|||||
| Ransomware | CS Cargo Group id6705 View details | Czechia | Transportation / Travel / Logistics | ||
|
Czech Republic |
|||||
| Ransomware | BMD Systemhaus id6703 View details | Austria | Other | ||
|
Austria |
|||||
| Ransomware | Buffalo Niagara Association id6702 View details | United States | NGOs / Associations | ||
|
United States |
|||||
| Ransomware | Abeko id6701 View details | Netherlands | Other | ||
|
Netherlands |
|||||
| Ransomware | NORANET - CZ id6700 View details | Czechia | Public Sector | ||
|
Czech Republic |
|||||
| Ransomware | Shows & Artists id6699 View details | Germany | Other | ||
|
Germany |
|||||
| Ransomware | Soroc id6676 View details | Canada | Other | ||
|
Canada |
|||||
| Ransomware | Black Cat Networks id6520 View details | Germany | Telecommunications | ||
|
Germany |
|||||
| Ransomware | Paragon Software Lanka id6519 View details | Sri Lanka | IT | ||
|
Sri Lanka |
|||||
| Ransomware | Royal Centre id6518 View details | Canada | Other | ||
|
Canada |
|||||
| Ransomware | Poly id6517 View details | United States | Public Sector | ||
|
California, United States |
|||||
| Ransomware | Mayberry Investments id6516 View details | Jamaica | Finance / Legal / Insurance | ||
|
Jamaica |
|||||
| Ransomware | Grupo Corporacion Control id6515 View details | Mexico | Services | ||
|
Mexico |
|||||
| Ransomware | Studioline Photography id6514 View details | Germany | Other | ||
|
Germany |
|||||
| Ransomware | Optimus Steel id6513 View details | United States | Manufacturing / Engineering | ||
|
United States |
|||||
| Ransomware | Xplain id6512 View details | Switzerland | Other | ||
|
Switzerland |
|||||
| Ransomware | Aria Online id6511 View details | United States | Public Sector | ||
|
Louisiana, United States |
|||||
| Ransomware | SOWITEC id6450 View details | Germany | Other | ||
|
Germany |
|||||
| Ransomware | Sauerbruch Hutton id6403 View details | Germany | Other | ||
|
Berlin, Germany |
|||||
| Ransomware | JP Maguire & Associates id6402 View details | United States | Public Sector | ||
|
Connecticut, United States |
|||||
| Ransomware | Germany id6401 View details | Germany | Other | ||
|
Berlin, Germany |
|||||
| Ransomware | KLC Network Services id6374 View details | United States | Telecommunications | — | |
|
Virginia, United States |
|||||
| Ransomware | SIVSA id6327 View details | Spain | IT | ||
|
Spaini - SIVSA Soluciones Informáticas is a consolidated company dedicated to the provision of services in the area of Information Technology, which with more than 25 years of experience in consulting and development, develops its business activity in Spain. |
|||||
| Ransomware | Coremain id6328 View details | Spain | Finance / Legal / Insurance | ||
|
Spaini - Coremain is a company that operates in the Financial Services industry. |
|||||
| Ransomware | Nova Group id6326 View details | Australia | Services | ||
|
Australia - Nova Group is a leading engineering services and technology solutions partner. Our vision is to solve the complex challenges that really matter to our clients. Nova's businesses include professional services provider Nova Systems, aerospace engineering firm |
|||||
| Ransomware | City of Lowell id6325 View details | United States | Public Sector | ||
|
Lowell, Massachusetts, United States |
|||||
| Ransomware | DGC id6324 View details | Sweden | Services | ||
|
information: DGC´s business concept is to develop and deliver customized IT services to customers who demand high security, availability and innovation. We deliver our services, from our own infrastructure as well as public clouds, with the highest service levels and a personal commitment to our customers.Our vision is to be recognized as the best supplier of customized IT services to customers who demand high security, availability and innovation. |
|||||
| Ransomware | Libra Virtua id6323 View details | Hungary | Communication / Marketing | ||
|
information: LIBRA VIRTUA provides the necessary LIBRA modules, the database manager, server capacity, backup and archiving, and all other related services. The compilation of the LIBRA modules and the service package depends on the needs of the user, who pays a usage-based monthly fee for the parameterized system. |
|||||
| Ransomware | Commune de Saxon id6322 View details | Switzerland | Public Sector | ||
|
Saxon, Switzerlandi ; Commune de Saxon is a company that operates in the Government industry. |
|||||
| Ransomware | Negma Business Solutions id6321 View details | United States | Services | ||
|
Texas, United Statesi - Founded in 1996, Negma Business Solutions, Inc. has been leading the way, providing businesses with expertly designed, secured, and dedicated infrastructures to house company networking and cloud equipment in a state-of-the-art, secured, multi-carrier facility. |
|||||
| Ransomware | Vocalcom id6320 View details | France | IT | ||
|
France - Vocalcom is a global provider of cloud technology which helps businesses win more customers, deliver faster, smarter service, and thrive. Loved by 550,000+ users for its innovative design and useful functionality, Vocalcom powers 3,600+ companies worldwide |
|||||
| Ransomware | Woonkracht10 id6319 View details | Netherlands | Retail / E-commerce | ||
|
Netherlandsi - Woonkracht10 is a housing corporation in the Drechtsteden region and manages more than 11,500 homes, shops and business premises. |
|||||
| Ransomware | Groupe Gambetta id6201 View details | France | Services | ||
|
France |
|||||
| Ransomware | UECC id6200 View details | Norway | Other | ||
|
Norway |
|||||
| Ransomware | Bang IT Solutions id6166 View details | Australia | Services | — | |
|
Australia |
|||||
| Ransomware | Huissiers id6165 View details | France | Other | ||
|
France |
|||||
| Ransomware | Coldiretti id6164 View details | Italy | Other | — | |
|
Italy |
|||||
| Ransomware | Corrib Oil id6163 View details | Ireland | Energy | — | |
|
Ireland |
|||||
| Ransomware | Structab AB (MegTax) id6162 View details | Sweden | Other | — | |
|
Sweden |
|||||
| Ransomware | CH Media id6107 View details | Switzerland | Communication / Marketing | — | |
|
Switzerland |
|||||
| Ransomware | PESA Bydgoszcz id6103 View details | Poland | Other | — | |
|
Poland |
|||||
| Ransomware | Palo Alto County Sheriff id6058 View details | United States | Public Sector | ||
|
Iowa, United States |
|||||
| Ransomware | PKF Antares id6057 View details | Canada | Other | ||
|
Canada |
|||||
| Ransomware | Legion Aero id6056 View details | United States | Public Sector | ||
|
United States |
|||||
| Ransomware | Vleeswarenfabriek Jac Michiels id6055 View details | Belgium | Other | ||
|
Belgium |
|||||
| Ransomware | Schirm id6054 View details | Germany | Other | ||
|
Germany |
|||||
| Ransomware | BMW France id5947 View details | France | Other | ||
|
France |
|||||
| Ransomware | Oscar Software id5946 View details | Finland | IT | ||
|
Finland |
|||||
| Ransomware | Jablite id5945 View details | United Kingdom | Other | ||
|
United Kingdom |
|||||
| Ransomware | Lightcast id5921 View details | Other | |||
|
USA |
|||||
| Ransomware | Optica id5920 View details | United States | Public Sector | ||
|
District of Columbia, United States |
|||||
| Ransomware | James, McElroy and Diehl id5919 View details | United States | Finance / Legal / Insurance | — | |
|
North Carolina, United States |
|||||
| Ransomware | Lysander Associates id5918 View details | United Kingdom | Other | ||
|
London, United Kingdom |
|||||
| Ransomware | TAC id5917 View details | Austria | Other | ||
|
Styria, Austria |
|||||
| Ransomware | Guyana Goldfields id5916 View details | Canada | Other | ||
|
Ontario, Canada |
|||||
| Ransomware | Picou Builders Supply id5915 View details | United States | Public Sector | ||
|
Louisiana, United States |
|||||
| Ransomware | Kk Mehta Cpa Associates id5914 View details | United States | Public Sector | ||
|
New York, United States |
|||||
| Ransomware | Pizza 73 id5913 View details | Canada | Other | ||
|
Alberta, Canada |
|||||
| Ransomware | Stanley Steemer id5765 View details | United States | Public Sector | ||
|
Ohio, United States |
|||||
| Ransomware | A&T group of companies id5764 View details | Poland | Services | ||
|
Poland |
|||||
| Ransomware | Berga Recycling id5763 View details | Canada | Other | ||
|
Quebec, Canada |
|||||
| Ransomware | Pine Tree Commercial Realty id5762 View details | United States | Public Sector | ||
|
Illinois, United States |
|||||
| Ransomware | Norman Shutters id5761 View details | United States | Public Sector | ||
|
Texas, United States |
|||||
| Ransomware | TaxAssist Accountants id5760 View details | United Kingdom | Other | ||
|
Norfolk, United Kingdom |
|||||
| Ransomware | draftPros id5759 View details | United States | Communication / Marketing | ||
|
Florida, United States |
|||||
| Ransomware | Royal Dirkzwager id5695 View details | Netherlands | Other | ||
|
Netherlands |
|||||
| Ransomware | Real Pro id5677 View details | United States | Communication / Marketing | ||
|
United States |
|||||
| Ransomware | Leemock id5676 View details | United States | Public Sector | ||
|
United States |
|||||
| Ransomware | The M. K. Morse id5675 View details | United States | Public Sector | ||
|
United States |
|||||
| Ransomware | Secure Wrap id5674 View details | United States | Public Sector | ||
|
United States |
|||||
| Ransomware | Russell Finex id5673 View details | United Kingdom | Other | ||
|
United Kingdom |
|||||
| Ransomware | Oakland id5564 View details | United States | Public Sector | — | |
|
United States |
|||||
| Ransomware | O???a?? id5559 View details | — | — | ||
|
USA |
|||||
| Ransomware | O???a?? id32050 View details | — | — | ||
|
USA |
|||||
| Ransomware | InPro electric id5520 View details | Germany | Communication / Marketing | — | |
|
Germany |
|||||
| Ransomware | I???o e???t??? id5498 View details | Germany | Other | — | |
|
Germany |
|||||
| Ransomware | Microgame SpA id5446 View details | Italy | Other | — | |
|
Italy |
|||||
| Ransomware | Energie Pool Schweiz id5445 View details | Switzerland | Other | — | |
|
Zurich, Switzerland |
|||||
| Ransomware | M???????? S?? id5393 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | A10 id5388 View details | United States | Telecommunications | — | |
|
A10 Network |
|||||
| Ransomware | Cave Beblenheim id5387 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | ACS id5386 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | L?? C??e id5379 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | ?C? id5378 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Point Dedicated Services id5357 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Helicar id5298 View details | Other | — | ||
|
No additional victim description available. |
|||||