Home · Wiki · Entities & Threat Actors
created: 2026-09-24 · updated: 2026-09-24 · type: entity · tags: [ransomware-group, supply-chain] · confidence: medium · affected_sectors: [] · au_impact: false

Play

Play is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a double-extortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.

Attribute Detail
ATT&CK ID G1040
Aliases
Attribution Not stated by MITRE ATT&CK
Class ecrime
Active since 2022 (per ATT&CK description)
ATT&CK entry created 2024-09-24
Techniques mapped 35

Attribution — as claimed

Not state-attributed; the activity is self-declared (public extortion/leak-site claims) or attributed to criminal reporting.

Known TTPs

Technique Name
T1003.001 LSASS Memory
T1016 System Network Configuration Discovery
T1018 Remote System Discovery
T1021.002 SMB/Windows Admin Shares
T1027.010 Command Obfuscation
T1030 Data Transfer Size Limits
T1048 Exfiltration Over Alternative Protocol
T1057 Process Discovery
T1059.001 PowerShell
T1059.003 Windows Command Shell
T1070.004 File Deletion
T1078 Valid Accounts

(First 12 of 35 ATT&CK-mapped techniques.)

Related Pages

  • Mitre Attack — the framework this page's data is drawn from
  • Silence — similarly attributed-linked actor, same attribution class
  • Lapsus — similarly attributed-linked actor, same attribution class
  • Scattered Spider — similarly attributed-linked actor, same attribution class

Provenance

Stub generated from MITRE ATT&CK G1040 on 2026-09-24. ATT&CK is the publisher of this page's technique and alias data; the attribution wording above is ATT&CK's, not this wiki's.