Ransomware group profile · #5 by claimed victims
Play ransomwarealso PlayCrypt, Balloonfly
Closed group, not operated as an affiliate programme, which makes its tradecraft unusually consistent between intrusions. Known for intermittent encryption and for a custom information stealer built for the reconnaissance stage.
Victimology
Who Play claims to have breached, from 1,316 leak-site posts recorded by VULONE.
Claims per month last 12 months
Top sectors
Top countries
Latest claimed victims 12 most recent
| Victim | Sector | Country | Claimed |
|---|---|---|---|
| Sys-kool | — | — | 10 Sep 2026 |
| Grunthal Welding & Supplies | — | — | 10 Sep 2026 |
| Sys-kool sys-kool.com | Technology | — | 10 Sep 2026 |
| Grunthal Welding & Supplies grunthalwelding.com | Manufacturing | CA | 10 Sep 2026 |
| Red Star Oil | — | — | 9 Sep 2026 |
| GT Distributors | — | — | 9 Sep 2026 |
| Red Star Oil redstaroil.com | Energy & Utilities | RS | 8 Sep 2026 |
| GT Distributors gtdist.com | Retail & E-Commerce | US | 8 Sep 2026 |
| MEQ mobiliermeq.com | Not Found | CA | 31 Aug 2026 |
| Figgins Family Wine Estates figginsfamily.com | Agriculture and Food Production | US | 31 Aug 2026 |
| KRC Machine Tool Solutions krcmachinetoolsolutions.com | Manufacturing | US | 31 Aug 2026 |
| Meteor Group meteor.de | Other | DE | 31 Aug 2026 |
All 1,316 Play victims, searchable
Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.
Tactics, techniques and procedures
5 MITRE ATT&CK techniques mapped to Play from public advisories and VULONE's own analysis.
| Tactic | Technique | Procedure | Confidence |
|---|---|---|---|
| Initial Access | T1133 External Remote Services | RDP and VPN with valid accounts. | Confirmed |
| Initial Access | T1190 Exploit Public-Facing Application | Exploited FortiOS (CVE-2018-13379, CVE-2020-12812) and Microsoft Exchange ProxyNotShell (CVE-2022-41040, CVE-2022-41082). | Confirmed |
| Discovery | T1087.002 Domain Account | AdFind and a custom stealer, Grixba, to enumerate the domain and inventory installed security software. | Confirmed |
| Impact | T1486 Data Encrypted for Impact | Intermittent encryption: only portions of each file are encrypted, which is faster and defeats detection that samples file entropy. | Confirmed |
| Defense Evasion | T1562.001 Disable or Modify Tools | GMER, IOBit and PowerTool used to disable endpoint protection. | Confirmed |
Tooling observed
Indicators, detections and the full playbook
Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.
Attack playbook
How a typical Play intrusion unfolds, section by section.
Encryption
Intermittent encryption — Encrypting only part of each file halves the time on target and undermines entropy-based detection. It is now common across several families and is a good reason to move detection towards behaviour and rate rather than f…
Frequently asked
Is Play ransomware still active?
How many victims has Play claimed?
Which industries does Play target?
Which countries are most affected by Play?
Where does VULONE get Play victim data?
VULONE research mentioning Play
Public sources
| Title | Publisher | Date |
|---|---|---|
| #StopRansomware: Play Ransomware (AA23-352A) | CISA / FBI / ACSC | 18 Dec 2023 |
Other ransomware groups
Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].