Play

MITRE ATT&CK: G1040 View on attack.mitre.org

Aliases: Play

First seen
2022-01-01 00:00:00
Primary motivation
financial-gain
Sophistication
advanced
Resource level
organization
Actor type
criminal
Related IoCs
66 (66 malicious)
Last IoC activity
2026-08-25 03:27:30
Profile updated
2026-07-07 12:30:35

Targeted industries: government-and-public-sector healthcare-and-pharmaceutical media-and-entertainment technology-and-telecommunications

Targeted regions: country_code:us country_code:br country_code:gb

Context

Play is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a double-extortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.

Recent IoC activity

66 malicious indicators in Maltiverse are attributed to Play (G1040). The 20 most recently updated:

TypeIndicatorUpdatedSources
file sample 2026-03-11_b04d56a0662120c5f1fc3e34511b686d_amadey_elex_hellokitty_play 2026-08-25 1
file sample f09d5ae1c73a1b47e027dc58db83c5dc814395dcd575cc588e7c174f3ef04265 2026-08-12 1
file sample 2026-03-16_3768c5f2c39a06baaf1cf94830d6a40a_amadey_cosmicduke_elex_play 2026-08-05 1
file sample 2026-07-12_0cf3c23415c786210ba8b21f25f8b78a_amadey_cobalt-strike_elex_play 2026-07-12 1
file sample d743728c1492063525534e1c67fc15e8bf241928f87cd64a509db8cb62955abe.exe 2026-06-22 2
file sample 2026-03-11_c6fd44e210047a19d582d60aecdc9e69_amadey_cobalt-strike_elex_play 2026-06-22 1
file sample 24906793171.zip 2026-04-14 1
file sample 2026-04-05_288511809b3163135dcd8faf22565f5d_amadey_cobalt-strike_elex_play 2026-04-05 1
file sample 2026-04-04_9d4a8c2c9d1a68aedc021536ac144801_amadey_elex_play 2026-04-04 1
file sample 2026-03-27_f42fc0a47d4ea240bad8d87492bd4847_amadey_cosmicduke_elex_play 2026-03-27 1
file sample 2026-03-16_3dc9fd2cdbd20c5c50cda454ba73d830_amadey_cosmicduke_elex_play 2026-03-16 1
file sample 2026-03-16_1588bab3f8ccd6279c6a7976a9ae2587_amadey_elex_hellokitty_play 2026-03-16 1
file sample 2026-03-16_509bae9d41213a0181f17230f6472d81_amadey_elex_play 2026-03-16 1
file sample 2026-03-15_f568fa61815622ec38d33ef6f5e85f3b_amadey_elex_play 2026-03-15 1
file sample 2026-03-15_c621281677fc9c2b79b4a6d6751a805d_amadey_elex_play 2026-03-15 1
file sample 2026-03-15_78971cd8313f35b4622580d9cb4ce402_amadey_elex_play 2026-03-15 1
file sample 2026-03-14_67f747f4cebc5991cbad66f553d184e0_amadey_elex_play 2026-03-14 1
file sample 2026-03-13_5ec17ee967083918a38b223b154b96a5_amadey_elex_hellokitty_metamorfo_play 2026-03-13 1
file sample 2026-03-13_0cb4c08c70d54ef2967f7a0b62a0b11a_amadey_elex_play 2026-03-13 1
file sample 2026-03-13_08121d921175cd36ca8bed29ff34bd53_amadey_elex_play 2026-03-13 1

Detection coverage

  • 159 YARA rules
  • 828 Sigma rules

Malware & tools used

  • System Network Configuration Discovery (attack-pattern)
  • Exfiltration Over Alternative Protocol (attack-pattern)
  • File Deletion (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • PowerShell (attack-pattern)
  • Archive via Utility (attack-pattern)
  • Remote System Discovery (attack-pattern)
  • Process Discovery (attack-pattern)
  • Command Obfuscation (attack-pattern)
  • Malware (attack-pattern)
  • Local Accounts (attack-pattern)
  • SMB/Windows Admin Shares (attack-pattern)
  • Clear Windows Event Logs (attack-pattern)
  • Valid Accounts (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Domain Accounts (attack-pattern)
  • System Information Discovery (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • External Remote Services (attack-pattern)
  • Tool (attack-pattern)
  • Exploit Public-Facing Application (attack-pattern)
  • LSASS Memory (attack-pattern)
  • Financial Theft (attack-pattern)
  • Disable or Modify Tools (attack-pattern)

Reports & references

  • MITRE ATT&CK — G1040 (report)
  • CISA — Aa23 352A (report)
  • Trend Micro — Ransomware Spotlight Play (report)

External references