Playcrypt

S1162

Malware.View on attack.mitre.org

About this malware

Playcrypt is a ransomware that has been used by Play since at least 2022 in attacks against against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Playcrypt derives its name from adding the .play extension to encrypted files and has overlap with tactics and tools associated with Hive and Nokoyawa ransomware and infrastructure associated with Quantum ransomware.

Techniques used3

Procedure examples3

TechniqueProcedure example
T1083
File and Directory Discovery

Playcrypt can avoid encrypting files with a .PLAY, .exe, .msi, .dll, .lnk, or .sys file extension.

T1486
Data Encrypted for Impact

Playcrypt encrypts files on targeted hosts with an AES-RSA hybrid encryption, encrypting every other file portion of 0x100000 bytes.

T1490
Inhibit System Recovery

Playcrypt can use AlphaVSS to delete shadow copies.

Groups that use it1

Campaigns0

None recorded.

References3

  1. CISA Play Ransomware Advisory December 2023 Open source
    CISA. (2023, December 18). #StopRansomware: Play Ransomware AA23-352A. Retrieved September 24, 2024.
  2. Microsoft PlayCrypt August 2022 Open source
    Microsoft Security Intelligence. (2022, August 27). Ransom:Win32/PlayCrypt.PA. Retrieved September 24, 2024.
  3. Trend Micro Ransomware Spotlight Play July 2023 Open source
    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.