Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Play Ransomware

124
Global rank
159 infographic chevron month
Month rank
155 infographic chevron week
Week rank
0
IOCs

Play aka PlayCrypt ransomware group has been successfully targeting corporations, municipal entities, and infrastruction all over the world for about three years. It infiltrates networks via software vulnerabilities, phishing links and compromised websites. The ransomware abuses Windows system services to evade detection and maintain persistence. Play encrypts user files and steals sensitive data while demanding a ransom.

Ransomware
Type
Unknown
Origin
1 March, 2022
First seen
15 December, 2025
Last seen
Also known as
PlayCrypt

How to analyze Play Ransomware with ANY.RUN

Type
Unknown
Origin
1 March, 2022
First seen
15 December, 2025
Last seen

IOCs

Last Seen at

Recent blog posts

post image
ANY.RUN & Tines: Scale SOC and Meet SLAs...
watchers 424
comments 0
post image
German Manufacturing Under Phishing Attacks:...
watchers 1914
comments 0
post image
CastleLoader Analysis: A Deep Dive into Steal...
watchers 4713
comments 0

What is Play ransomware?

Play aka PlayCrypt is relatively new yet already notorious ransomware group active since mid-2022. It has impacted a wide range of businesses and critical infrastructure in North America, South America, and Europe.

It is based on double extortion technique and has intermittent encryption as its signature feature. Partial encryption is completed much faster, besides, it prevents detection by security solutions that monitor files for extensive modifications.

It infiltrates the targeted system by exploiting vulnerabilities in public-facing applications, such as Microsoft Exchange Server. It is also distributed via phishing emails containing malicious attachments or links. Malicious ads and compromised websites has also been detected as distribution vehicles.

Play Ransomware ransom note in the ANY.RUN Sandbox Play Ransomware ransom note shown in the ANY.RUN sandbox

To move laterally within the network and deploy the ransomware payload, it abuses the legitimate tools and built-in system utilities (e.g., PowerShell, PsExec, Cobalt Strike).

After exfiltrating sensitive data, the ransomware encrypts files, adds the .play extension, and leaves a ransom note in each affected directory containing instructions on how to pay the ransom.

Play ransomware uses anti-analysis techniques to evade detection by security software, creates scheduled tasks and modifies registry entries to maintain persistence.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Play ransomware technical details

Play Ransomware is equipped with advanced capabilities focused on maximizing impact on the victims’ infrastructure:

  • Double Extortion: Data encryption and theft for increased ransom leverage.
  • Partial File Encryption: Evades detection, speeds encryption by encrypting file portions rather than entire files.
  • Security Disabling: Disables security systems to facilitate encryption and maintain persistence.
  • Log Removal: Removes system logs to obscure activity and hinder forensics.
  • Lateral Movement: Spreads within networks, increasing attack scope and leverage.
  • Network Reconnaissance: Uses NetScan for network topology and target identification to enable lateral movement.
  • Credential Dumping: Employs Mimikatz for credential extraction to facilitate privilege escalation and lateral movement.
  • Privilege Escalation: Leverages publicly available Windows Privilege Escalation Awesome Scripts for privilege escalation, enabling system-level access.
  • Remote Control: Utilizes AnyDesk and Cobalt Strike for persistent remote access, command execution, and potential data exfiltration.

Play execution process

Let’s upload the Play Ransomware to ANY.RUN’s Interactive Sandbox for analysis to see how it operates.

Play Ransomware analysis in the ANY.RUN Sandbox Play Ransomware analysis session in the ANY.RUN sandbox

A typical Play ransomware attack begins with gaining initial access to the victim’s network via exploiting public-facing applications or abusing valid accounts.

Once inside the targeted environment, the malware focuses on stealth by heavily relying on Living Off the Land Binaries (LOLBins). To facilitate lateral movement and execute files, Play may use command-and-control applications like Cobalt Strike or SystemBC.

Play Ransomware analysis in the ANY.RUN Sandbox Play Ransomware process analysis in the ANY.RUN sandbox

Before encrypting files, Play ransomware operators exfiltrate data. They do this by splitting compromised data into segments, compressing files, and transferring them to actor-controlled accounts.

After exfiltration, the ransomware encrypts files using an AES-RSA hybrid approach with intermittent encryption while skipping system files.

Encrypted files are appended with the .play extension, and a ransom note named ReadMe.txt is placed in the file directory on the C:\ partition.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Collect Cyber Threat Intelligence on Play Ransomware

To get the most current information about Play Ransomware, use Threat Intelligence Lookup. It contains data extracted from millions of public malware analyses conducted in ANY.RUN’s Interactive Sandbox.

You can use over 40 different search parameters, including specific IPs, domains, file names, or even mutexes. Using these filters, you can quickly gather important details about threats like Play Ransomware.

For example, if you were investigating Play Ransomware, you could start by directly searching for its name within the Threat Intelligence Lookup. Or, if you had other clues like unique file codes (hashes) or website connections it uses, you could search with those instead.

Play Ransomware search results in TI Lookup Search results for Play Ransomware in TI Lookup

A simple and effective search would be to use the search term: threatName:"Play". This type of search will show you a list of sandbox reports associated with Play Ransomware. You can then explore these reports to get a deep understanding of exactly how this ransomware works and what it does.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Play distribution methods

Play Ransomware commonly gains initial access through several attack vectors. Compromised Remote Desktop Protocol (RDP) servers are a frequent entry point, often due to weak security configurations. Attackers exploit known vulnerabilities like CVE-2020-12812 in RDP services to bypass authentication and gain unauthorized system access.

Another prevalent method involves exploiting CVE-2022-41040, the ProxyNotShell vulnerability in Microsoft Exchange, allowing for remote code execution directly on vulnerable servers.

Conclusion

Play Ransomware poses a serious risk to organizations. Its blend of advanced techniques, such as partial encryption and lateral movement, coupled with readily exploitable entry points like RDP and VPN vulnerabilities, requires comprehensive security attention.

To prevent Play Ransomware infections, organizations can analyze suspicious files and URLs in ANY.RUN's Interactive Sandbox. The service provides fast insights into the malicious behavior and allows users to manually engage with threats in a safe environment just like on a standard computer.

Sign up for a free ANY.RUN account

HAVE A LOOK AT

Qilin Ransomware screenshot
Qilin ransomware (predecessor known as “Agenda”) is a rapidly evolving ransomware-as-a-service (RaaS) operation targeting organizations worldwide. Known for double extortion tactics (encrypting files while also threatening to leak stolen data) Qilin has quickly gained notoriety for its customization, flexibility, and impact on critical infrastructure.
Read More
Stealc screenshot
Stealc
stealc
Stealc is a stealer malware that targets victims’ sensitive data, which it exfiltrates from browsers, messaging apps, and other software. The malware is equipped with advanced features, including fingerprinting, control panel, evasion mechanisms, string obfuscation, etc. Stealc establishes persistence and communicates with its C2 server through HTTP POST requests.
Read More
Virlock screenshot
Virlock
virlock
Virlock is a unique ransomware strain that combines encryption capabilities with file infection techniques. First observed in 2014, it stands out due to its polymorphic nature and ability to embed its code into compromised files, ensuring continued propagation. Once it infects a system, it encrypts files and locks the screen, demanding a ransom for file recovery and system access.
Read More
Interlock screenshot
Interlock
interlock
Interlock is a relatively recent entrant into the ransomware landscape. First identified in 2023, it's a multi-functional malware strain used in ransomware-as-a-service (RaaS) operations.
Read More
Keylogger screenshot
Keylogger
keylogger
A keylogger is a type of spyware that infects a system and has the ability to record every keystroke made on the device. This lets attackers collect personal information of victims, which may include their online banking credentials, as well as personal conversations. The most widespread vector of attack leading to a keylogger infection begins with a phishing email or link. Keylogging is also often present in remote access trojans as part of an extended set of malicious tools.
Read More
Akira Ransomware screenshot
Akira Ransomware emerged in March 2023 and compromised over 250 organizations by January 2024 with approximately $42 million in ransom payments. It employs double extortion tactics exfiltrating data before encryption and threatening to publish it on a dedicated website.
Read More