Playcrypt
MITRE ATT&CK: S1162 View on attack.mitre.org
Aliases: Play, Playcrypt
- First seen
- 2022-01-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Operating systems
- windows
- Last IoC activity
- 2026-07-12 14:22:48
- Profile updated
- 2026-07-07 13:21:20
Targeted industries: government-and-public-sector healthcare-and-pharmaceutical media-and-entertainment
Targeted regions: country_code:us country_code:br country_code:de
Context
Playcrypt is a ransomware that has been used by Play since at least 2022 in attacks against against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Playcrypt derives its name from adding the .play extension to encrypted files and has overlap with tactics and tools associated with Hive and Nokoyawa ransomware and infrastructure associated with Quantum ransomware.
Detection coverage
- 1 YARA rules
- 55 Sigma rules
Malware & tools used
- Data Encrypted for Impact (attack-pattern)
- Inhibit System Recovery (attack-pattern)
- File and Directory Discovery (attack-pattern)
Used by threat actors
- Play (threat-actor)
Detection rules
- MALPEDIA_Win_Play_Auto (yara-rule)
Reports & references
- CISA — Aa23 352A (report)
- Trend Micro — Ransomware Spotlight Play (report)
- MITRE ATT&CK — S1162 (report)
- Microsoft — Malware Encyclopedia Description (report)