← All ransomware groups

Ransomware group profile · #5 by claimed victims

Play ransomwarealso PlayCrypt, Balloonfly

Closed group, not operated as an affiliate programme, which makes its tradecraft unusually consistent between intrusions. Known for intermittent encryption and for a custom information stealer built for the reconnaissance stage.

Active First seen Jun 2022 ATT&CK G1040 AES-RSA hybrid with intermittent encryption of file chunks
1,316Victims claimed on leak sites
18Victims in the last 30 days
48Victims in the last 90 days
46Countries hit
31Leak-site URLs tracked, 3 online
10 Sep 2026Latest claim recorded

Victimology

Who Play claims to have breached, from 1,316 leak-site posts recorded by VULONE.

Claims per month last 12 months

Oct 2025: 26OctNov 2025: 27Dec 2025: 22Jan 2026: 35JanFeb 2026: 42Mar 2026: 46Apr 2026: 4AprMay 2026: 17Jun 2026: 16Jul 2026: 15JulAug 2026: 21Sep 2026: 8

Top sectors

Manufacturing347
Professional Services301
Technology166
Retail & E-Commerce98
Transportation73
Agriculture and Food Production64
Financial Services47
Hospitality45

Top countries

United States939
Canada96
United Kingdom41
Germany37
Netherlands17
Sweden15
Switzerland10
Australia9

Latest claimed victims 12 most recent

VictimSectorCountryClaimed
Sys-kool 10 Sep 2026
Grunthal Welding & Supplies 10 Sep 2026
Sys-kool sys-kool.com Technology 10 Sep 2026
Grunthal Welding & Supplies grunthalwelding.com Manufacturing CA 10 Sep 2026
Red Star Oil 9 Sep 2026
GT Distributors 9 Sep 2026
Red Star Oil redstaroil.com Energy & Utilities RS 8 Sep 2026
GT Distributors gtdist.com Retail & E-Commerce US 8 Sep 2026
MEQ mobiliermeq.com Not Found CA 31 Aug 2026
Figgins Family Wine Estates figginsfamily.com Agriculture and Food Production US 31 Aug 2026
KRC Machine Tool Solutions krcmachinetoolsolutions.com Manufacturing US 31 Aug 2026
Meteor Group meteor.de Other DE 31 Aug 2026

All 1,316 Play victims, searchable

Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.

Start free Sign in

Tactics, techniques and procedures

5 MITRE ATT&CK techniques mapped to Play from public advisories and VULONE's own analysis.

TacticTechniqueProcedureConfidence
Initial Access T1133 External Remote Services RDP and VPN with valid accounts. Confirmed
Initial Access T1190 Exploit Public-Facing Application Exploited FortiOS (CVE-2018-13379, CVE-2020-12812) and Microsoft Exchange ProxyNotShell (CVE-2022-41040, CVE-2022-41082). Confirmed
Discovery T1087.002 Domain Account AdFind and a custom stealer, Grixba, to enumerate the domain and inventory installed security software. Confirmed
Impact T1486 Data Encrypted for Impact Intermittent encryption: only portions of each file are encrypted, which is faster and defeats detection that samples file entropy. Confirmed
Defense Evasion T1562.001 Disable or Modify Tools GMER, IOBit and PowerTool used to disable endpoint protection. Confirmed

Tooling observed

Indicators, detections and the full playbook

Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.

See full IOCs

Attack playbook

How a typical Play intrusion unfolds, section by section.

Encryption

Intermittent encryption — Encrypting only part of each file halves the time on target and undermines entropy-based detection. It is now common across several families and is a good reason to move detection towards behaviour and rate rather than f…

Frequently asked

Is Play ransomware still active?
Play is tracked as active. The most recent leak-site claim VULONE recorded is dated 10 September 2026. 18 victims were claimed in the last 30 days.
How many victims has Play claimed?
VULONE has recorded 1,316 leak-site victim claims attributed to Play since November 2022, across 46 countries and 14 sectors.
Which industries does Play target?
The sectors most often named on the Play leak site are Manufacturing, Professional Services, Technology.
Which countries are most affected by Play?
Most Play victims recorded by VULONE are located in United States, Canada, United Kingdom.
Where does VULONE get Play victim data?
Claims are collected continuously from the group's own leak sites and cross-checked with ransomware.live and RansomLook. A claim is the group's assertion, not a confirmed breach.

VULONE research mentioning Play

Public sources

TitlePublisherDate
#StopRansomware: Play Ransomware (AA23-352A)CISA / FBI / ACSC18 Dec 2023

Other ransomware groups

Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].