Play ransomware, also referred to as PlayCrypt, represents an advanced and evolving cyber threat. Noted for its global impact, this ransomware group employs a double-extortion model, encrypting systems after exfiltrating sensitive data. Known from mid-2022, the group and malware have shown increased sophistication and activity since this past June.
Play’s operations have targeted a broad spectrum of organizations spanning North America (United States, Canada), South America (Brazil, Argentina), and Europe (Germany, Belgium, Switzerland, and more), with a significant focus on critical infrastructure sectors such as manufacturing, healthcare, and retail. The group uses double extortion tactics, encrypting organizational data and threatening to publish it on public Tor-based sites.
The attackers often gain access by abusing existing account credentials and exploiting weaknesses in Remote Desktop Protocol (RDP) servers and Fortinet SSL VPNs. They also use tools such as Grixba to map out network configurations and identify antivirus software. More recently, the group has developed and deployed a Linux variant of the ransomware component, targeting vulnerable VMWare ESXi environments. This variant went undetected for a while until being reported on by Trend Micro, rapidly expanding the group’s victim base and extortion capabilities.
The group behind Play frequently seeks out and exploits insecurely stored credentials on compromised networks, using tools like Mimikatz for credential dumping. Ultimately, they encrypt all the data and utilize double extortion to demand ransom payments. The ransom note left by Play is notably simplistic, featuring solely the word “PLAY” alongside an email address for victim communication, typically located at the root of the hard drive (often C:).
To prevent PlayCrypt and other ransomware attacks, it is recommended to take the following measures:
If compromise is detected, organizations should: