created: 2026-09-24 · updated: 2026-09-24 · type: entity · tags: [ransomware-group, supply-chain] · confidence: medium · affected_sectors: [] · au_impact: false
Play
Play is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a double-extortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.
| Attribute | Detail |
|---|---|
| ATT&CK ID | G1040 |
| Aliases | — |
| Attribution | Not stated by MITRE ATT&CK |
| Class | ecrime |
| Active since | 2022 (per ATT&CK description) |
| ATT&CK entry created | 2024-09-24 |
| Techniques mapped | 35 |
Attribution — as claimed
Not state-attributed; the activity is self-declared (public extortion/leak-site claims) or attributed to criminal reporting.
Known TTPs
| Technique | Name |
|---|---|
T1003.001 |
LSASS Memory |
T1016 |
System Network Configuration Discovery |
T1018 |
Remote System Discovery |
T1021.002 |
SMB/Windows Admin Shares |
T1027.010 |
Command Obfuscation |
T1030 |
Data Transfer Size Limits |
T1048 |
Exfiltration Over Alternative Protocol |
T1057 |
Process Discovery |
T1059.001 |
PowerShell |
T1059.003 |
Windows Command Shell |
T1070.004 |
File Deletion |
T1078 |
Valid Accounts |
(First 12 of 35 ATT&CK-mapped techniques.)
Related Pages
- Mitre Attack — the framework this page's data is drawn from
- Silence — similarly attributed-linked actor, same attribution class
- Lapsus — similarly attributed-linked actor, same attribution class
- Scattered Spider — similarly attributed-linked actor, same attribution class
Provenance
Stub generated from MITRE ATT&CK G1040 on 2026-09-24. ATT&CK is the publisher of this page's technique and alias data; the attribution wording above is ATT&CK's, not this wiki's.