Ransomware
Play
Ransomware
10 detections found
Also known as: Playcrypt, PlayCrypt Ransomware, Play Ransomware Group
Play (deploying the Playcrypt encryptor) is a closed, non-advertised ransomware operation active since June 2022 that uses double extortion and intermittent encryption, frequently exploiting FortiOS, Exchange, Citrix, and remote-management-tool vulnerabilities (e.g., SimpleHelp CVE-2024-57727) for initial access. It has compromised an estimated 900+ organizations across North America, South America, and Europe, including critical infrastructure, and remains active with no major law-enforcement disruption as of September 2026; CISA/FBI updated their joint advisory in mid-2025 to reflect evolving TTPs.
Detection & eradication references
Curated links to authoritative sources — MITRE ATT&CK, CISA advisories, law-enforcement takedown announcements, and vendor threat-intel writeups — for removal, remediation, and further technical detail. Sigma Watch does not publish its own removal steps here, since malware behavior and tooling change too fast for a static write-up to stay reliably accurate.
- #StopRansomware: Play Ransomware — CISA/FBI/ASD's ACSC
- Play, Group G1040 — MITRE ATT&CK
- FBI, CISA warn Play ransomware targeting critical infrastructure with evolving techniques — Cybersecurity Dive
Detection rules
| Source | Rule | Status | Updated |
|---|---|---|---|
| splunk | AWS Bedrock Claude Possible Prompt Injection | production | 2026-07-06 |
| sigma | Potential Privileged System Service Operation - SeLoadDriverPrivilege | test | 2026-06-29 |
| splunk | Cisco Smart Install Port Discovery and Status | production | 2026-05-13 |
| sigma | Grixba Malware Reconnaissance Activity | experimental | 2025-11-26 |
| suricata | ET DYN_DNS DYNAMIC_DNS HTTP Request to a *.play .ai Domain | rev 3 | 2024-06-11 |
| suricata | ET DYN_DNS DYNAMIC_DNS Query to a *.play .ai Domain | rev 3 | 2024-06-11 |
| suricata | ET WEB_CLIENT Possible Android RCE via XSS and Play Store XFO | rev 4 | 2024-03-14 |
| snort | ET INFO DYNAMIC_DNS HTTP Request to a *.play .ai Domain | rev 2 | 2023-03-02 |
| snort | ET INFO DYNAMIC_DNS Query to a *.play .ai Domain | rev 2 | 2023-03-02 |
| snort | ET WEB_CLIENT Possible Android RCE via XSS and Play Store XFO | rev 1 | 2015-02-11 |