Playcrypt

MITRE ATT&CK: S1162 View on attack.mitre.org

Aliases: Play, Playcrypt

First seen
2022-01-01 00:00:00
Malware type
ransomware
Family
Malware family
Operating systems
windows
Last IoC activity
2026-07-12 14:22:48
Profile updated
2026-07-07 13:21:20

Targeted industries: government-and-public-sector healthcare-and-pharmaceutical media-and-entertainment

Targeted regions: country_code:us country_code:br country_code:de

Context

Playcrypt is a ransomware that has been used by Play since at least 2022 in attacks against against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Playcrypt derives its name from adding the .play extension to encrypted files and has overlap with tactics and tools associated with Hive and Nokoyawa ransomware and infrastructure associated with Quantum ransomware.

Detection coverage

  • 1 YARA rules
  • 55 Sigma rules

Malware & tools used

  • Data Encrypted for Impact (attack-pattern)
  • Inhibit System Recovery (attack-pattern)
  • File and Directory Discovery (attack-pattern)

Used by threat actors

  • Play (threat-actor)

Detection rules

  • MALPEDIA_Win_Play_Auto (yara-rule)

Reports & references

  • CISA — Aa23 352A (report)
  • Trend Micro — Ransomware Spotlight Play (report)
  • MITRE ATT&CK — S1162 (report)
  • Microsoft — Malware Encyclopedia Description (report)

External references