CARDS
CARDS
Play is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a double-extortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.
This profile is generated from the same canonical actor-card record used by the Threat Actor Cards directory, so aliases, targeting fields, activity notes, and source links stay aligned as the database is enriched.
Actor Card Detail
Entity Type1
Ransomware/extortion association reported in public sources; confirm brand/affiliate relationships per incident.
First Seen1
2024-09-24
Last Seen1
ATT&CK record modified 2024-10-02; operational last-seen varies by source
Profile Updated1
May 24, 2026, 8:00 PM EDT
Victim Count
Not available
Origin1
Unknown
Motivation1
Financial
Primary Access Pattern1
Enterprise identity, exposed services, remote access, endpoint, backup, and data-exfiltration paths.
Objective1
Financial
Identity
Aliases1
Source Boundary
attack.mitre.org is the retained baseline for this profile. IntelliOS preserves source labels as discovery and comparison signals until a cited source explicitly supports a merge, split, or actor-boundary change.
Targeting
Target Countries / Exposure
Target Sectors
Associated Activity1
ATT&CK IDs1
Campaign Context
| Campaign / Operation | Source-Backed Context |
|---|---|
| play Ransomware / Extortion Operations4 | play Ransomware / Extortion Operations is retained in the campaign database for play. Initially observed in June 2022, the Play ransomware (a.k.a PlayCrypt) operates through double extortion, targeting numerous organizations in Latin America. Its Initial Access method is quite similar to other ransomwares, involving attacks such as Phishing, Exposed Services to the Internet, and Valid Account compromises.<br> <br> On April 19, 2023, the security company Symantec published two new tools developed by the Play group. These tools allow the malicious actor to enumerate and exfiltrate data from the... |
Indicators
SOCRadar reports an unstated number of IOCs for this profile. IntelliOS currently retains 24 cited public observable/context rows; this is not the full possible public-source IOC corpus.
Source coverage: 3 source groups tracked; 1 currently contributes retained observable or context rows.
Retained Observables
Showing 24 of 24
| Type | Value | Source |
|---|---|---|
| SHA-256 Hash | 0E408AED1ACF902A9F97ABF71CF0DD354024109C5D52A79054C421BE35D935492 | CISA AA23-352A |
| SHA-256 Hash | 1409E010675BF4A40DB0A845B60DB3AAE5B302834E80ADEEC884AEBC55ECCBF72 | CISA AA23-352A |
| SHA-256 Hash | 372F7B45A141BB0709D578BC716CBCA03104258822C4290CCBEB6002238501582 | CISA AA23-352A |
| SHA-256 Hash | 453257C3494ADDAFB39CB6815862403E827947A1E7737EB8168CD10522465DEB2 | CISA AA23-352A |
| SHA-256 Hash | 47B7B2DD88959CD7224A5542AE8D5BCE928BFC986BF0D0321532A7515C244A1E2 | CISA AA23-352A |
| SHA-256 Hash | 511F63455CA4F83B0347B65DDA17585AD02591A9F23D8E234E5CE1321AA3381A2 | CISA AA23-352A |
| SHA-256 Hash | 6DE8DD5757F9A3AC5E2AC28E8A77682D7A29BE25C106F785A061DCF582A20DC62 | CISA AA23-352A |
| SHA-256 Hash | 75404543DE25513B376F097CEB383E8EFB9C9B95DA8945FD4AA37C7B2F2262122 | CISA AA23-352A |
| SHA-256 Hash | 75B525B220169F07AECFB3B1991702FBD9A1E170CAF0040D1FCB07C3E819F54A2 | CISA AA23-352A |
| SHA-256 Hash | 7A42F96599DF8090CF89D6E3CE4316D24C6C00E499C8557A2E09D61C00C119862 | CISA AA23-352A |
| SHA-256 Hash | 7DEA671BE77A2CA5772B86CF8831B02BFF0567BCE6A3AE023825AA40354F8ACA2 | CISA AA23-352A |
| SHA-256 Hash | 859165041D75FBA3759C5533E324225F355C8A07B4645B984192AD6BEF06DB1A2 | CISA AA23-352A |
| SHA-256 Hash | 90040340EE101CAC7831D7035230AC8AD4224D432E5636F34F13AA1C4A0C20412 | CISA AA23-352A |
| SHA-256 Hash | 967DAFF362E63FF45526F585B7944488ACE1BB5BB5B30FA40D56557F1C538D092 | CISA AA23-352A |
| SHA-256 Hash | C59F3C8D61D940B56436C14BC148C1FE98862921B8F7BAD97FBC96B31D71193C2 | CISA AA23-352A |
| SHA-1 Hash | 3D86555ACAA19AEDDB5896071D1E3711B062EDBE2 | CISA AA23-352A |
| Filename | fThe9C.exe2 | CISA AA23-352A |
| Filename | Gt_net.exe2 | CISA AA23-352A |
| Filename | Hi.exe2 | CISA AA23-352A |
| Filename | HRsword.exe2 | CISA AA23-352A |
| Filename | PSexesvc.exe2 | CISA AA23-352A |
| Filename | SVCHost.dll2 | CISA AA23-352A |
| Filename | Usysdiag.exe2 | CISA AA23-352A |
| Campaign Context | Thin Play row backfilled from the same CISA/FBI/ASD ACSC source set as the SOCRadar Play Ransomware card; IntelliOS retains duplicate-card boundaries for reader interpretation.2 | CISA AA23-352A |
| Source | Reported | Retained | Coverage Status |
|---|---|---|---|
| SOCRadar | N/A | 0 | Profile retained; no SOCRadar IOC count currently stored. |
| CISA/FBI/ASD ACSC2 | N/A | 24 | Public observables or source-context rows retained and displayed. |
| MITRE ATT&CK / CTI1 | N/A | 0 | Technique and identity context retained; not treated as raw IOC feed for this card. |
IntelliOS Intel Products
None Found
Source Reconciliation
| Source | Primary Name | Treatment | Boundary |
|---|---|---|---|
| attack.mitre.org | Play | Baseline actor-card record retained for the current profile view. | Fields reflect the retained database record. Additional source consensus, collisions, and canonical identity mappings can be layered into this profile without automatically merging actors. |
| IntelliOS | Play | Normalizes this record for directory search, card display, profile lookup, and future product linking. | Normalization is a presentation and workflow aid; it is not an independent attribution claim. |
Citations
| # | Source | Use In Card |
|---|---|---|
| 1 | MITRE ATT&CK https://attack.mitre.org/groups/G1040/ | Canonical ATT&CK group, campaign, software, aliases, and technique mapping source where matched. |
| 2 | CISA AA23-352A: StopRansomware Play Ransomware https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-352a | IOC Source |
| 3 | Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024. https://www.trendmicro.com/vinfo/us/security/news/ransomware-spotlight/ransomware-spotlight-play | Trend Micro Ransomware Spotlight Play July 2023 |
| 4 | play - Ransomware.live group profile https://www.ransomware.live/group/play | Ransomware.live campaign row source for play Ransomware / Extortion Operations. |
Source Collision Notes
IntelliOS starts this detail page from the retained source record for Play.
No possible same-actor, alias reuse, sub-cluster, duplicate-boundary, or external-source collision is currently retained for this actor.
| Collision Source | Candidate Records | Shared Evidence | Treatment |
|---|---|---|---|
| None retained | No candidate records | No shared evidence recorded | No collision action needed. |
| External sources | Mandiant, CrowdStrike, other non-SOCRadar sources | None retained | External collisions are shown separately when retained. |