Play
Medium ConfidenceHigh ThreatPlayCrypt • Balloonfly
Play ransomware, also known as PlayCrypt, is a ransomware operation that emerged in mid-2022. The group targets organizations across various sectors including government, healthcare, and manufacturing. Play ransomware is known for exploiting vulnerabilities in Microsoft Exchange servers and FortiOS for initial access. The group employs intermittent encryption techniques to speed up the encryption process and evade detection.
Play ransomware, also known as PlayCrypt, is a ransomware operation that emerged in mid-2022. The group targets organizations across various sectors including government, healthcare, and manufacturing. Play ransomware is known for exploiting vulnerabilities in Microsoft Exchange servers and FortiOS for initial access. The group employs intermittent encryption techniques to speed up the encryption process and evade detection.
Target Sectors
Target Regions
Attributed to Cybercriminal (No State Sponsor) (Russia). Attribution confidence: Medium.
Future Outlook
Play is expected to continue operations targeting Government sectors.
First observed activity of Play
Continued active operations