Threat group.View on attack.mitre.org
Play is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a double-extortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
Play has used Mimikatz and the Windows Task Manager to dump LSASS process memory. |
| T1016 System Network Configuration Discovery |
Play has used the information-stealing tool Grixba to enumerate network information. |
| T1018 Remote System Discovery |
Play has used tools such as AdFind, Nltest, and BloodHound to enumerate shares and hostnames on compromised networks. |
| T1021.002 SMB/Windows Admin Shares |
Play has used Cobalt Strike to move laterally via SMB. |
| T1027.010 Command Obfuscation |
Play has used Base64-encoded PowerShell scripts for post exploit activities on compromised hosts. |
| T1030 Data Transfer Size Limits |
Play has split victims' files into chunks for exfiltration. |
| T1048 Exfiltration Over Alternative Protocol |
Play has used WinSCP to exfiltrate data to actor-controlled accounts. |
| T1057 Process Discovery |
Play has used the information stealer Grixba to check for a list of security processes. |
| T1059.001 PowerShell |
Play has used Base64-encoded PowerShell scripts to disable Microsoft Defender. |
| T1059.003 Windows Command Shell |
Play has used a batch script to remove indicators of its presence on compromised hosts. |
| T1070.004 File Deletion |
Play has used tools including Wevtutil to remove malicious files from compromised hosts. |
| T1078 Valid Accounts |
Play has used valid VPN accounts to achieve initial access. |
| T1078.002 Domain Accounts |
Play has used valid domain accounts for access. |
| T1078.003 Local Accounts |
Play has used valid local accounts to gain initial access. |
| T1082 System Information Discovery |
Play has leveraged tools to enumerate system information. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.