Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now

Play Ransomware

125
Global rank
91 infographic chevron month
Month rank
95 infographic chevron week
Week rank
0
IOCs

Play aka PlayCrypt ransomware group has been successfully targeting corporations, municipal entities, and infrastruction all over the world for about three years. It infiltrates networks via software vulnerabilities, phishing links and compromised websites. The ransomware abuses Windows system services to evade detection and maintain persistence. Play encrypts user files and steals sensitive data while demanding a ransom.

Ransomware
Type
Unknown
Origin
1 March, 2022
First seen
10 March, 2025
Last seen
Also known as
PlayCrypt

How to analyze Play Ransomware with ANY.RUN

Type
Unknown
Origin
1 March, 2022
First seen
10 March, 2025
Last seen

IOCs

Last Seen at

Recent blog posts

post image
New Pre-Installed Dev Tools for Deep Sandbox...
watchers 290
comments 0
post image
AI Safety: Key Threats and Solutions 
watchers 383
comments 0
post image
5 Common Evasion Techniques in Malware 
watchers 551
comments 0

What is Play ransomware?

Play aka PlayCrypt is relatively new yet already notorious ransomware group active since mid-2022. It has impacted a wide range of businesses and critical infrastructure in North America, South America, and Europe.

It is based on double extortion technique and has intermittent encryption as its signature feature. Partial encryption is completed much faster, besides, it prevents detection by security solutions that monitor files for extensive modifications.

It infiltrates the targeted system by exploiting vulnerabilities in public-facing applications, such as Microsoft Exchange Server. It is also distributed via phishing emails containing malicious attachments or links. Malicious ads and compromised websites has also been detected as distribution vehicles.

Play Ransomware ransom note in the ANY.RUN Sandbox Play Ransomware ransom note shown in the ANY.RUN sandbox

To move laterally within the network and deploy the ransomware payload, it abuses the legitimate tools and built-in system utilities (e.g., PowerShell, PsExec, Cobalt Strike).

After exfiltrating sensitive data, the ransomware encrypts files, adds the .play extension, and leaves a ransom note in each affected directory containing instructions on how to pay the ransom.

Play ransomware uses anti-analysis techniques to evade detection by security software, creates scheduled tasks and modifies registry entries to maintain persistence.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Play ransomware technical details

Play Ransomware is equipped with advanced capabilities focused on maximizing impact on the victims’ infrastructure:

  • Double Extortion: Data encryption and theft for increased ransom leverage.
  • Partial File Encryption: Evades detection, speeds encryption by encrypting file portions rather than entire files.
  • Security Disabling: Disables security systems to facilitate encryption and maintain persistence.
  • Log Removal: Removes system logs to obscure activity and hinder forensics.
  • Lateral Movement: Spreads within networks, increasing attack scope and leverage.
  • Network Reconnaissance: Uses NetScan for network topology and target identification to enable lateral movement.
  • Credential Dumping: Employs Mimikatz for credential extraction to facilitate privilege escalation and lateral movement.
  • Privilege Escalation: Leverages publicly available Windows Privilege Escalation Awesome Scripts for privilege escalation, enabling system-level access.
  • Remote Control: Utilizes AnyDesk and Cobalt Strike for persistent remote access, command execution, and potential data exfiltration.

Play execution process

Let’s upload the Play Ransomware to ANY.RUN’s Interactive Sandbox for analysis to see how it operates.

Play Ransomware analysis in the ANY.RUN Sandbox Play Ransomware analysis session in the ANY.RUN sandbox

A typical Play ransomware attack begins with gaining initial access to the victim’s network via exploiting public-facing applications or abusing valid accounts.

Once inside the targeted environment, the malware focuses on stealth by heavily relying on Living Off the Land Binaries (LOLBins). To facilitate lateral movement and execute files, Play may use command-and-control applications like Cobalt Strike or SystemBC.

Play Ransomware analysis in the ANY.RUN Sandbox Play Ransomware process analysis in the ANY.RUN sandbox

Before encrypting files, Play ransomware operators exfiltrate data. They do this by splitting compromised data into segments, compressing files, and transferring them to actor-controlled accounts.

After exfiltration, the ransomware encrypts files using an AES-RSA hybrid approach with intermittent encryption while skipping system files.

Encrypted files are appended with the .play extension, and a ransom note named ReadMe.txt is placed in the file directory on the C:\ partition.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Collect Cyber Threat Intelligence on Play Ransomware

To get the most current information about Play Ransomware, use Threat Intelligence Lookup. It contains data extracted from millions of public malware analyses conducted in ANY.RUN’s Interactive Sandbox.

You can use over 40 different search parameters, including specific IPs, domains, file names, or even mutexes. Using these filters, you can quickly gather important details about threats like Play Ransomware.

For example, if you were investigating Play Ransomware, you could start by directly searching for its name within the Threat Intelligence Lookup. Or, if you had other clues like unique file codes (hashes) or website connections it uses, you could search with those instead.

Play Ransomware search results in TI Lookup Search results for Play Ransomware in TI Lookup

A simple and effective search would be to use the search term: threatName:"Play". This type of search will show you a list of sandbox reports associated with Play Ransomware. You can then explore these reports to get a deep understanding of exactly how this ransomware works and what it does.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Play distribution methods

Play Ransomware commonly gains initial access through several attack vectors. Compromised Remote Desktop Protocol (RDP) servers are a frequent entry point, often due to weak security configurations. Attackers exploit known vulnerabilities like CVE-2020-12812 in RDP services to bypass authentication and gain unauthorized system access.

Another prevalent method involves exploiting CVE-2022-41040, the ProxyNotShell vulnerability in Microsoft Exchange, allowing for remote code execution directly on vulnerable servers.

Conclusion

Play Ransomware poses a serious risk to organizations. Its blend of advanced techniques, such as partial encryption and lateral movement, coupled with readily exploitable entry points like RDP and VPN vulnerabilities, requires comprehensive security attention.

To prevent Play Ransomware infections, organizations can analyze suspicious files and URLs in ANY.RUN's Interactive Sandbox. The service provides fast insights into the malicious behavior and allows users to manually engage with threats in a safe environment just like on a standard computer.

Sign up for a free ANY.RUN account

HAVE A LOOK AT

Loader screenshot
Loader
loader downloader
A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.
Read More
Akira Ransomware screenshot
Akira Ransomware emerged in March 2023 and compromised over 250 organizations by January 2024 with approximately $42 million in ransom payments. It employs double extortion tactics exfiltrating data before encryption and threatening to publish it on a dedicated website.
Read More
AsyncRAT screenshot
AsyncRAT
asyncrat
AsyncRAT is a RAT that can monitor and remotely control infected systems. This malware was introduced on Github as a legitimate open-source remote administration software, but hackers use it for its many powerful malicious functions.
Read More