Ransomware Group intelligence
Play
ActiveTrack Play with 1349 published victims and 5 known leak locations in a single intelligence view.
Overview
Play is tracked by Breach House as a ransomware group with 1349 published victims.
United States is currently the most targeted country in this dataset.
5 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (5)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 5 | Onion service | Up checked 4h ago | ipi4tiumgzjsym6pyuzrfqrtwskokxokqannmd6sa24shvr7x5kxdvqd.onion |
| Leak location 4 | Onion service | Up checked 4h ago | j75o7xvvsm4lpsjhkjvb4wl2q6ajegvabe6oswthuaubbykk4xkzgpid.onion |
| Leak location 1 | Onion service | Down checked 4h ago | mbrlkbtq5jonaqkurjwmxftytyn2ethqvbxfu4rgjbkkknndqwae6byd.onion |
| Leak location 3 | Onion service | Down checked 4h ago | mbrlkbtq5jonaqkurjwmxftytyn2ethqvbxfu4rgjbkkknndqwae6byd.onion |
| Leak location 2 | Onion service | Down checked 4h ago | k7kg3jqxang3wh7hnmaiokchk7qoebupfgoik6rha6mjpzwupwtj25yd.onion |
Top Activity Sectors (17)
- Public Sector 588
- Not identified 227
- Services 77
- Manufacturing / Engineering 72
- Communication / Marketing 66
- IT 63
- Finance / Legal / Insurance 54
- Construction / Real Estate 42
- Energy 21
- Agriculture / Food 19
- Transportation / Travel / Logistics 19
- Hospitality / Food & Beverage / Tourism 16
- Retail / E-commerce 15
- Telecommunications 11
- NGOs / Associations 6
- Healthcare / Pharma 4
- Education 2
Typical Attacks (28)
▼How Play typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via Play, Playcrypt.
-
T1587.001 Malware Resource Development
What they do: Play developed and employ Playcrypt ransomware.
What that means: Adversaries may develop malware and malware components that can be used during targeting.
-
T1588.002 Tool Resource Development
What they do: Play has used multiple tools for discovery and defense evasion purposes on compromised hosts.
What that means: Adversaries may buy, steal, or download software tools that can be used during targeting.
-
What they do: Play has used valid VPN accounts to achieve initial access.
What that means: Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
What they do: Play has used valid domain accounts for access.
What that means: Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
What they do: Play has used valid local accounts to gain initial access.
What that means: Adversaries may obtain and abuse credentials of a local account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
What they do: Play has used Remote Desktop Protocol (RDP) and Virtual Private Networks (VPN) for initial access.
What that means: Adversaries may leverage external-facing remote services to initially access and/or persist within a network.
-
T1190 Exploit Public-Facing Application Initial Access
What they do: Play has exploited known vulnerabilities for initial access including CVE-2018-13379 and CVE-2020-12812 in FortiOS and CVE-2022-41082 and CVE-2022-41040 ("ProxyNotShell") in Microsoft Exchange.
What that means: Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
-
T1059.001 PowerShell Execution
What they do: Play has used Base64-encoded PowerShell scripts to disable Microsoft Defender.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1059.003 Windows Command Shell Execution
What they do: Play has used a batch script to remove indicators of its presence on compromised hosts.
What that means: Adversaries may abuse the Windows command shell for execution.
-
T1027.010 Command Obfuscation Stealth
What they do: Play has used Base64-encoded PowerShell scripts for post exploit activities on compromised hosts.
What that means: Adversaries may obfuscate content during command execution to impede detection.
-
T1070.004 File Deletion Stealth
What they do: Play has used tools including Wevtutil to remove malicious files from compromised hosts.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: Play has used tools including GMER, IOBit, and PowerTool to disable antivirus software.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1685.005 Clear Windows Event Logs Defense Impairment
What they do: Play has used tools to remove log files on targeted systems.
What that means: Adversaries may clear Windows Event Logs to hide the activity of an intrusion.
-
T1003.001 LSASS Memory Credential Access
What they do: Play has used Mimikatz and the Windows Task Manager to dump LSASS process memory.
What that means: Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).
-
T1016 System Network Configuration Discovery Discovery
What they do: Play has used the information-stealing tool Grixba to enumerate network information.
What that means: Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems.
-
T1018 Remote System Discovery Discovery
What they do: Play has used tools such as AdFind, Nltest, and BloodHound to enumerate shares and hostnames on compromised networks.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1057 Process Discovery Discovery
What they do: Play has used the information stealer Grixba to check for a list of security processes.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1082 System Information Discovery Discovery
What they do: Play has leveraged tools to enumerate system information.
What that means: An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture.
-
T1083 File and Directory Discovery Discovery
What they do: Play has used the Grixba information stealer to list security files and processes.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1518.001 Security Software Discovery Discovery
What they do: Play has used the information-stealing tool Grixba to scan for anti-virus software.
What that means: Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: Play has used Cobalt Strike to move laterally via SMB.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1560.001 Archive via Utility Collection
What they do: Play has used WinRAR to compress files prior to exfiltration.
What that means: Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration.
-
T1105 Ingress Tool Transfer Command and Control
What they do: Play has used Cobalt Strike to download files to compromised machines.
What that means: Adversaries may transfer tools or other files from an external system into a compromised environment.
-
T1030 Data Transfer Size Limits Exfiltration
What they do: Play has split victims' files into chunks for exfiltration.
What that means: An adversary may exfiltrate data in fixed size chunks instead of whole files or limit packet sizes below certain thresholds.
-
T1048 Exfiltration Over Alternative Protocol Exfiltration
What they do: Play has used WinSCP to exfiltrate data to actor-controlled accounts.
What that means: Adversaries may steal data by exfiltrating it over a different protocol than that of the existing command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: Playcrypt encrypts files on targeted hosts with an AES-RSA hybrid encryption, encrypting every other file portion of 0x100000 bytes.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: Playcrypt can use AlphaVSS to delete shadow copies.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
-
T1657 Financial Theft Impact
What they do: Play demands ransom payments from victims to unencrypt filesystems and to not publish sensitive data exfiltrated from victim networks.
What that means: Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims.
Tools Observed (11)
▼Software Play has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Defense evasion
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Networking & tunnelling
Offensive security tooling
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (3)
▼The note this group leaves on a compromised machine. Click a filename to read it.
ReadMe2.txt
Your network has been encrypted. Your private, personal, corporate, confidential data has been stolen. If you do not resolve the issue, your data will be published on our leak portal. News portal, tor network links: ipi4tiumgzjsym6pyuzrfqrtwskokxokqannmd6sa24shvr7x5kxdvqd.onion j75o7xvvsm4lpsjhkjvb4wl2q6ajegvabe6oswthuaubbykk4xkzgpid.onion contact email: [email protected] PLAY Ransomware Team
ReadMe.txt
PLAY news portal, tor network links: mbrlkbtq5jonaqkurjwmxftytyn2ethqvbxfu4rgjbkkknndqwae6byd.onion k7kg3jqxang3wh7hnmaiokchk7qoebupfgoik6rha6mjpzwupwtj25yd.onion [email protected]
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (1349)
Search, filter and paginate the victim timeline for Play. Showing 101–200 of 1349.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Northern Mechanical Contractors id29099 View details | Canada | Other | ||
|
United States |
|||||
| Ransomware | ACC Construction id29100 View details | United States | Construction / Real Estate | ||
|
United States |
|||||
| Ransomware | IWC Food Service id29101 View details | United States | Other | ||
|
United States |
|||||
| Ransomware | Ashcroft Homes id29102 View details | Canada | Other | ||
|
Canada |
|||||
| Ransomware | DURAND-WAYLAND id29103 View details | United States | Other | ||
|
United States |
|||||
| Ransomware | K & E Distributing id28957 View details | United States | Other | ||
|
United States |
|||||
| Ransomware | Accessoires Outillage Ltee id28958 View details | Canada | Other | ||
|
Canada |
|||||
| Ransomware | EMA Engineering & Consulting id28959 View details | United States | Services | ||
|
United States |
|||||
| Ransomware | Crystal Point id27936 View details | United States | IT | ||
|
United States |
|||||
| Ransomware | Morphosis id27935 View details | United States | Construction / Real Estate | ||
|
United States |
|||||
| Ransomware | Barnes Solicitors LLP id27893 View details | United Kingdom | Finance / Legal / Insurance | ||
|
United Kingdom |
|||||
| Ransomware | Sokolin id27892 View details | United States | Retail / E-commerce | ||
|
United States |
|||||
| Ransomware | Brokk id27739 View details | Sweden | Manufacturing / Engineering | ||
|
Sweden |
|||||
| Ransomware | Colorado Construction id27738 View details | United States | Construction / Real Estate | ||
|
United Kingdom |
|||||
| Ransomware | Lucky Look id27737 View details | Germany | Communication / Marketing | ||
|
Germany |
|||||
| Ransomware | Weber Kracht & Chellew id27736 View details | United States | Finance / Legal / Insurance | ||
|
United States |
|||||
| Ransomware | Specflue id27735 View details | United Kingdom | Manufacturing / Engineering | ||
|
United Kingdom |
|||||
| Ransomware | Kivells id27734 View details | United Kingdom | Construction / Real Estate | ||
|
United Kingdom |
|||||
| Ransomware | Dock Pros id27733 View details | United States | Construction / Real Estate | ||
|
United States |
|||||
| Ransomware | Ampex Data Systems id27732 View details | United States | Manufacturing / Engineering | ||
|
United States |
|||||
| Ransomware | Valley Plating Inc id27731 View details | United States | Manufacturing / Engineering | ||
|
United States |
|||||
| Ransomware | Witt UK Group id27730 View details | United Kingdom | Manufacturing / Engineering | ||
|
United Kingdom |
|||||
| Ransomware | TPIS Industrial Services id27601 View details | United States | Services | ||
|
United States |
|||||
| Ransomware | All Real Estate Title Solutions id27553 View details | United States | Services | ||
|
United States |
|||||
| Ransomware | Roxiticus Golf Club id27552 View details | United States | Hospitality / Food & Beverage / Tourism | ||
|
United States |
|||||
| Ransomware | Pinnacle id27551 View details | United States | Finance / Legal / Insurance | ||
|
United States |
|||||
| Ransomware | Ascent Asset Group id27550 View details | United States | Finance / Legal / Insurance | ||
|
United States |
|||||
| Ransomware | Capital Wholesale Drug id27549 View details | United States | Healthcare / Pharma | ||
|
United States |
|||||
| Ransomware | Block Engineering id27548 View details | United States | Manufacturing / Engineering | ||
|
United States |
|||||
| Ransomware | Window & Door Design Center of Florida id27547 View details | United States | Finance / Legal / Insurance | ||
|
United States |
|||||
| Ransomware | Knight's Site Services id27387 View details | United States | Services | ||
|
United States |
|||||
| Ransomware | Gsolutionz id27386 View details | United States | Other | ||
|
United States |
|||||
| Ransomware | Executive Aviation id27349 View details | United States | Other | ||
|
United States |
|||||
| Ransomware | Circle Floors id27292 View details | United States | Public Sector | ||
|
United States |
|||||
| Ransomware | Eagle Industrial Equipment id27291 View details | United States | Manufacturing / Engineering | ||
|
United States |
|||||
| Ransomware | Infinity Systems id27200 View details | United States | Public Sector | ||
|
United States |
|||||
| Ransomware | Serrano Industries id27199 View details | United States | Public Sector | ||
|
United States |
|||||
| Ransomware | Helen Kaminski id27198 View details | Australia | Public Sector | ||
|
United States |
|||||
| Ransomware | Byard F Brogan id27197 View details | United States | Public Sector | ||
|
United States |
|||||
| Ransomware | Facilities USA id27196 View details | United States | Public Sector | ||
|
United States |
|||||
| Ransomware | Southern Concrete Construction id27195 View details | United States | Construction / Real Estate | ||
|
United States |
|||||
| Ransomware | T a Solberg id27152 View details | Norway | Public Sector | ||
|
United States |
|||||
| Ransomware | Don E Bower id27151 View details | United States | Public Sector | ||
|
United States |
|||||
| Ransomware | Design To Print id27150 View details | United States | Communication / Marketing | ||
|
United States |
|||||
| Ransomware | Select Tool id27149 View details | Canada | Other | ||
|
Canada |
|||||
| Ransomware | DFW Aero Mechanix id27148 View details | United States | Public Sector | ||
|
United States |
|||||
| Ransomware | Garland Williams & Associates id27147 View details | United States | Public Sector | ||
|
United States |
|||||
| Ransomware | Equine Canada id27029 View details | Canada | Other | ||
|
Canada |
|||||
| Ransomware | GapVax id27028 View details | United States | Public Sector | ||
|
United States |
|||||
| Ransomware | Gordon/Clifford Realty id26988 View details | United States | Services | ||
|
United States |
|||||
| Ransomware | Cabka id26987 View details | Germany | Other | ||
|
Germany |
|||||
| Ransomware | The Kuker Group id26986 View details | United States | Finance / Legal / Insurance | ||
|
United States |
|||||
| Ransomware | LRA Constructors id26985 View details | United States | Public Sector | ||
|
United States |
|||||
| Ransomware | Cobblestone Creek Country Club id26984 View details | United States | Public Sector | ||
|
United States |
|||||
| Ransomware | Project Consulting Services id26983 View details | United States | Services | ||
|
United States |
|||||
| Ransomware | Go Professional Cases id26982 View details | United States | Communication / Marketing | ||
|
United States |
|||||
| Ransomware | WCC Technologies Group id26981 View details | United States | IT | ||
|
United States |
|||||
| Ransomware | Favaro Lavezzo Gill Caretti id26980 View details | United States | Public Sector | ||
|
United States |
|||||
| Ransomware | Landmark Rehab Group id26882 View details | United States | Public Sector | ||
|
United States |
|||||
| Ransomware | BT Services id26881 View details | United Kingdom | Services | ||
|
United States |
|||||
| Ransomware | Integrity Building id26880 View details | United States | Construction / Real Estate | ||
|
United States |
|||||
| Ransomware | Atlantic Design Engineers id26733 View details | United States | Public Sector | ||
|
United States |
|||||
| Ransomware | Faulkner+Locke id26732 View details | United States | Public Sector | ||
|
United States |
|||||
| Ransomware | Hendrick Construction id26731 View details | United States | Construction / Real Estate | ||
|
United States |
|||||
| Ransomware | Young & Associates Consulting Engineers id26730 View details | United States | Services | ||
|
United States |
|||||
| Ransomware | PenLink id26729 View details | United States | Public Sector | ||
|
Penlink is a US-based digital intelligence company that serves public safety, law enforcement, national security, and other government-focused users. Its platform and services help organizations analyze open-source intelligence and digital evidence, and support investigative and threat-analysis workflows. The company presents itself as a global provider of compliant, certified solutions for complex data analysis and government use cases. It was listed as a ransomware victim associated with play. |
|||||
| Ransomware | [Redacted] Ticket #2021 id26854 View details | United States | Public Sector | ||
|
United States |
|||||
| Ransomware | Gulfstream Services id26728 View details | United States | Services | ||
|
United States |
|||||
| Ransomware | Chemical Computing Group id26727 View details | Canada | Manufacturing / Engineering | ||
|
Canada |
|||||
| Ransomware | Marwood id26678 View details | United States | Public Sector | ||
|
United States |
|||||
| Ransomware | Sika Technology id26677 View details | Switzerland | IT | ||
|
New Zealand |
|||||
| Ransomware | Paisley Products of Canada id26676 View details | Canada | Communication / Marketing | ||
|
Canada |
|||||
| Ransomware | Kirbor Homes id26675 View details | United States | Public Sector | ||
|
United States |
|||||
| Ransomware | Tropic Tool & Mold id26674 View details | United States | Public Sector | ||
|
United States |
|||||
| Ransomware | Arizona Lighting Sales id26673 View details | United States | Retail / E-commerce | ||
|
United States |
|||||
| Ransomware | Indianapolis Car Exchange id26672 View details | United States | Public Sector | ||
|
United States |
|||||
| Ransomware | Oklahoma Auto Exchange id26671 View details | United States | Public Sector | ||
|
United States |
|||||
| Ransomware | Auto Auction of New England id26670 View details | United States | Public Sector | ||
|
United States |
|||||
| Ransomware | Spring Brook Country Club id26669 View details | United States | Communication / Marketing | ||
|
United States |
|||||
| Ransomware | Branagh id26577 View details | United States | Public Sector | ||
|
United States |
|||||
| Ransomware | Heartland Title Services id26495 View details | United States | Services | ||
|
United States |
|||||
| Ransomware | UCG Associates id26494 View details | United States | Energy | ||
|
United States |
|||||
| Ransomware | Unified Engineering id26493 View details | United States | Manufacturing / Engineering | ||
|
Canada |
|||||
| Ransomware | HMA id26492 View details | United States | Communication / Marketing | ||
|
United States |
|||||
| Ransomware | Lusamerica Foods id26491 View details | United States | Agriculture / Food | ||
|
United States |
|||||
| Ransomware | Altak id26441 View details | United States | Public Sector | ||
|
United States |
|||||
| Ransomware | Catalanatto & Barnes id26440 View details | United States | Hospitality / Food & Beverage / Tourism | ||
|
United States |
|||||
| Ransomware | Makivik id26439 View details | Canada | Other | ||
|
Canada |
|||||
| Ransomware | Northbridge id26437 View details | United States | Public Sector | ||
|
United States |
|||||
| Ransomware | Milwaukee Forge id26409 View details | United States | Public Sector | ||
|
United States |
|||||
| Ransomware | Carlton Scale id26277 View details | United States | Public Sector | ||
|
United States |
|||||
| Ransomware | De Gruyter Brill id26276 View details | Netherlands | Public Sector | ||
|
United States |
|||||
| Ransomware | ESS Metron id26275 View details | United States | Public Sector | ||
|
United States |
|||||
| Ransomware | Ilderton Contracting id26274 View details | United States | Public Sector | ||
|
United States |
|||||
| Ransomware | Bloom's Bus Lines id26273 View details | United States | Public Sector | ||
|
United States |
|||||
| Ransomware | RAL Companies id26272 View details | United States | Public Sector | ||
|
United States |
|||||
| Ransomware | KaiserAir id26271 View details | United States | Public Sector | ||
|
United States |
|||||
| Ransomware | ISTS id26216 View details | United States | Public Sector | ||
|
United States |
|||||
| Ransomware | CBH Homes id26215 View details | United States | Public Sector | ||
|
United States |
|||||
| Ransomware | Woodfield id26214 View details | United States | Public Sector | ||
|
United States |
|||||