All threat actors

PLAY is a ransomware group active since at least 2022, deploying Playcryp ransomware against sectors such as business, government, critical infrastructure, healthcare, and media in North America, South America, and Europe. The group employs a double-extortion model, encrypting systems after exfiltrating data. Security researchers presume PLAY operates as a closed group.

Also known as

Play Ransomware Group

Create a free account to see the reports

Sign in or create a free account to see every report that names PLAY.

Create free account