Play
G104061 reportsaliases · Play
61
Reports
12
Techniques
6
Tactics
14
Countries
57%
Hunt coverage
1
Aliases
Analyst assessment — key judgments
- Signature techniques: T1589.001 (Credentials), T1590.005 (IP Addresses), T1684 (Social Engineering).
- Primary targeting: US, CA, BR, ES.
- Tooling observed: play.
- Steady activity: 15 report(s) in last 30d vs 19 prior (-21%).
- Recent movement: 8 new technique(s), 173 new infrastructure indicator(s) in the last 30 days.
- Hunt coverage 57% of 28 observed techniques (12 gap(s)).
- Assessment confidence: medium (61).
Activity & trend
SteadyLast 30d: 15 vs 19 prior (-21%)· first reported 2025-05-26 · last 2026-09-18
3
7d
15
30d
36
90d
61
All
2.8
Rpts/wk
Reporting timeline · 12 months
Movement — last 30 days
New techniques
T1053.005T1593.001T1059.007T1003.007T1552.004T1552.003T1573T1543.002Dropped (90d+)
T1557T1684.001T1608.006AML.T0073AML.T0016.002Targeting gained
BRCNDEIEVNTargeting lost
FRIDITRUTRNew infrastructure
vistahelps.comhttp://ipi4tiumgzjsym6pyuzrfqrtwskokxokqinglewoodgolfclub.cahttp://ipi4tiumgzjsym6pyuzrfqrtwskokxokqbarrettmahony.comhttp://ipi4tiumgzjsym6pyuzrfqrtwskokxokqsys-kool.comhttp://ipi4tiumgzjsym6pyuzrfqrtwskokxokqgrunthalwelding.comhttp://ipi4tiumgzjsym6pyuzrfqrtwskokxokqredstaroil.comhttp://ipi4tiumgzjsym6pyuzrfqrtwskokxokqOverview
Analyst triage
Intelligence summary
Play is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a double-extortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.(Citation: CISA Play Ransomware Advisory December 2023)(Citation: Trend Micro Ransomware Spotlight Play July 2023)
Top co-occurring indicators
Aliases & naming
Targeting · countries
Targeting · named victims
ATT&CK technique matrix
Coverage vs hunt library:
—
Hunt-coverage gaps — prioritized
Top techniques by observation
- T1589.001 · Credentialsconf 756
- T1590.005 · IP Addressesconf 703
- T1684 · Social Engineeringconf 703
- T1087.003 · Email Accountconf 652
- T1557 · Adversary-in-the-Middleconf 601
- T1684.001 · Impersonationconf 601
- T1608.006 · SEO Poisoningconf 601
- AML.T0073 · Impersonationconf 601
- AML.T0016.002 · Generative AIconf 601
- T1588.007 · Artificial Intelligenceconf 601
- T1588.006 · Vulnerabilitiesconf 601
- T1586.003 · Cloud Accountsconf 601
Threat catalogue · engineering roadmap
Flagged detection-engineering queue
Uncovered techniques you flagged for hunt / detection build-out, aggregated across every actor you visit. Stored locally in your browser.
Infrastructure
IOC type mix
Tooling / malware families
Relationships
Activity
30-day mention timeline
Recent reporting
| Title | Source | Severity | Collected |
|---|