Play
MITRE ATT&CK: G1040 View on attack.mitre.org
Aliases: Play
- First seen
- 2022-01-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- advanced
- Resource level
- organization
- Actor type
- criminal
- Related IoCs
- 66 (66 malicious)
- Last IoC activity
- 2026-08-25 03:27:30
- Profile updated
- 2026-07-07 12:30:35
Targeted industries: government-and-public-sector healthcare-and-pharmaceutical media-and-entertainment technology-and-telecommunications
Targeted regions: country_code:us country_code:br country_code:gb
Context
Play is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a double-extortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.
Recent IoC activity
66 malicious indicators in Maltiverse are attributed to Play (G1040). The 20 most recently updated:
Detection coverage
- 159 YARA rules
- 828 Sigma rules
Malware & tools used
- System Network Configuration Discovery (attack-pattern)
- Exfiltration Over Alternative Protocol (attack-pattern)
- File Deletion (attack-pattern)
- Windows Command Shell (attack-pattern)
- PowerShell (attack-pattern)
- Archive via Utility (attack-pattern)
- Remote System Discovery (attack-pattern)
- Process Discovery (attack-pattern)
- Command Obfuscation (attack-pattern)
- Malware (attack-pattern)
- Local Accounts (attack-pattern)
- SMB/Windows Admin Shares (attack-pattern)
- Clear Windows Event Logs (attack-pattern)
- Valid Accounts (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Domain Accounts (attack-pattern)
- System Information Discovery (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Security Software Discovery (attack-pattern)
- External Remote Services (attack-pattern)
- Tool (attack-pattern)
- Exploit Public-Facing Application (attack-pattern)
- LSASS Memory (attack-pattern)
- Financial Theft (attack-pattern)
- Disable or Modify Tools (attack-pattern)
Reports & references
- MITRE ATT&CK — G1040 (report)
- CISA — Aa23 352A (report)
- Trend Micro — Ransomware Spotlight Play (report)