ShellCodeX
Tools • Events • News • Insights
SEO Checker
Threat Group Profile

play

● Active — last 30 days
Victim claims 62
First seen Apr 2026
Last activity 20 Aug 2026
Tracked since Nov 2022

Group overview

Initially observed in June 2022, the Play ransomware (a.k.a PlayCrypt) operates through double extortion, targeting numerous organizations in Latin America. Its Initial Access method is quite similar to other ransomwares, involving attacks such as Phishing, Exposed Services to the Internet, and Valid Account compromises. On April 19, 2023, the security company Symantec published two new tools developed by the Play group. These tools allow the malicious actor to enumerate and exfiltrate data from the internal network. The post mentions the following: 'Play threat actors use the .NET infostealer to enumerate software and services via WMI, WinRM, Remote Registry, and Remote Service. The malware checks for the existence of security and backup software, as well as remote administration tools and other programs, saving the information in .CSV files that are compressed into a .ZIP file for later manual exfiltration by threat actors.'Source: https://github.com/crocodyli/ThreatActors-TTPs

Preferred targets

Technology · 8 Manufacturing · 7 Business Services · 6 Consumer Services · 4 Construction · 4 Financial Services · 4

Most targeted countries

US · 38 CA · 4 DE · 3 GB · 3 NL · 3 AU · 1

Tactics & techniques (MITRE ATT&CK)

Initial Access

Valid Accounts Valid Accounts: Domain Accounts Valid Accounts: Local Accounts External Remote Services Exploit Public-Facing Application

Execution

Scheduled Task/Job: Scheduled Task Command and Scripting Interpreter Command and Scripting Interpreter: PowerShell Command and Scripting Interpreter: Windows Command Shell

Persistence

Valid Accounts: Domain Accounts Valid Accounts: Local Accounts External Remote Services

Privilege Escalation

Valid Accounts: Domain Accounts Valid Accounts: Local Accounts

Defense Evasion

Obfuscated Files or Information Indicator Removal Indicator Removal: Clear Windows Event Logs Domain or Tenant Policy Modification Domain or Tenant Policy Modification: Group Policy Modification Disable or Modify Tools

Stealth

Obfuscated Files or Information: Command Obfuscation Indicator Removal: File Deletion Valid Accounts: Domain Accounts Valid Accounts: Local Accounts

Credential Access

OS Credential Dumping OS Credential Dumping: LSASS Memory OS Credential Dumping: NTDS Unsecured Credentials

Discovery

System Network Configuration Discovery Remote System Discovery Network Service Discovery Process Discovery System Information Discovery File and Directory Discovery Account Discovery: Domain Account Software Discovery

Victim Claims Timeline

Back to radar
🇺🇸 United States

Crystal Point

www.crystalpoint.com

United States

🇺🇸 United States

Morphosis

www.morphosis.com

United States

Technology