26
Techniques
9
Toolsets
2
CVEs Referenced
1
KEV Entries
CISA Known Exploited
About Play

Play is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a double-extortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.

View MITRE record ↗

Toolsets (9)
🐛
Malware · Linux, macOS, Windows
🐛
Playcrypt S1162
Malware · Windows
🔧
AdFind S0552
Tool · Windows
🔧
Tool · Windows
🔧
Empire S0363
Tool · Linux, macOS, Windows
🔧
Mimikatz S0002
Tool · Windows
🔧
Nltest S0359
Tool · Windows
🔧
PsExec S0029
Tool · Windows
🔧
Wevtutil S0645
Tool · Windows
CVEs Referenced (2 · 1 CISA KEV)
CVE-2014-7169View full details on NVDKEV
CVE-2016-6662View full details on NVD
↑