Ransomware needs a way in. Stolen credentials are the cheapest one.
Play Ransomware Ransomware Group
Ransomware group profile
Description
Play Ransomware is a rapidly emerging ransomware group known for its targeted attacks on sectors like healthcare, education, and finance. The group distinguishes itself by employing both innovative techniques and traditional tactics, focusing on organizations with perceived weak cybersecurity defenses.
Key insights
- •Utilizes a double extortion model, encrypting data and exfiltrating sensitive information with threats of public release.
- •Targets sectors like healthcare, education, and finance, exploiting vulnerabilities in their systems.
- •Engages in sophisticated spear-phishing campaigns to gain initial access.
Threat Level & Status Breakdown
For Play Ransomware · Based on incidents in selected period
Recent activity
Monthly attack count for Play Ransomware in the selected period
Intelligence
IOCs, YARA/Sigma rules, and related families for Play Ransomware
- 8ebddd79bb7ef1b9fcbc1651193b002bfef598fd
- fd6c16a31f96e0fd65db5360a8b5c179a32e3b8e
- 4508d0254431df5a59692d7427537df8a424dbba
- 7e8aeba19d804b8f2e7bffa7c6e4916cf3dbee62
- c198971f84a74e972142c6203761b81f8f854d2c
- 6cf281fc9795d5e94054cfe222994209779d0ba6
- cc9cd337b28752b8ba1f41f773a3eac1876d8233
- 5ed4d42d0dcc929b7f1d29484b713b3b2dee88e3
- 8abd64e0c4515d27fae4de74841e66cfc4371575
- 3affa67bc7789fd349f8a6c9e28fa1f0c453651f
- fadd8a6c816bebe3924e0b4542549f55c5283db8
- 4589b97225ba3e4a4f382540318fa8ce724132d5
- 1e5920a6b79a93b1fa8daca32e13d1872da208ee
- 783cd767b496577038edbe926d008166ebe1ba8c
- 79e41b93b540f6747d0d2c3a22fd45ab0eac09ab
- 65300576ba66f199fca182c7002cb6701106f91c
- d94448afd4841981b1b49ecf63db3b63cb208853
- b1e0abfdaa655cf29b44d5848fab253c43d5350a
- 33dba9c156f6ceda40aefa059dea6ef19a767ab2
- 5d3160f01920a6b11e3a23baec1ed9c6d8d37a68
- 0830ef2fe7813ccf6821cad71a22e4384b4d02b4
- de055a89de246e629a8694bde18af2b1605e4b9b493c7e4aef669dd67acf5085
- 14ba3fa927a06224dfe587014299e834def4644f
- 7574cf2c64f35161ab1292e2f532aabf
- 00020cfe58fe9be476347ffb8318f9bcd031aef36ea71b2f5fab95d6507e71fd
- 59ac7dd41dca19a25a78a242e93a7ded
- 57db3bb722a00419191d267dba57a77d011f77c0c74d753172b22d3810f97c69
- accf036232d2570796bf0abf71ffe342dc35e2f07b12041fe739d44a06f36af8
- 937216d5260f3e76138be16831052b04c710e15d91756124d8d6755d2766ff4b
- 7f731cc11f8e4d249142e99a44b9da7a48505ce32c4ee4881041beeddb3760be
- 9585af44c3ff8fd921c713680b0c2b3bbc9d56add848ed62164f7c9b9f23d065
- 0c0e0f9b09b80d87ebc88e2870907b6cacb4cd7703584baf8f2be1fd9438696d
- c9c94ac5e1991a7db42c7973e328fceeb6f163d9f644031bdfd4123c7b3898b0
- 0ee1d284ed663073872012c7bde7fac5ca1121403f1a5d2d5411317df282796c
- 000105e9c8d938ce6eeadbfaf39a69772e1132d1eaae7c6bcbe06a115520a0f3
- f78a870573f5bf2f15570e286257fae7
- eaccbf47cd42836b0e21ab2196b86d98a28733ca
- 356ca8abf11d97bf9dcbff47c04bf1ddcb8685ef84d38e6850ec6c28a37655b9
- 388a796580234efc95f3b1c70ad4cb44bfddc7ba0f9203bf4902b9929b136f95
- 51ffc0b7358b7611492ef458fdf9b97f121e49e70f86a6b53b93ed923b707a03
- b087e1309f3eab6302d7503079af1ad6af06d70a932f7a6ae1421b942048e28a
- f84da76ddaf196d12a600f6f4ddda2e2
- 4398670073785d6569ca16b371cac2cdd9007ab3
- 000354e64e175f3f7712448e6b192a5f674e9276c2cc0d42724b5bb6ba8bd8a2
TTPs & Attack Vectors
Tools, initial access, and MITRE ATT&CK techniques for Play Ransomware
T1486
T1486
T1490
T1490
T1078
T1078
T1080
T1080
T1021
T1021
T1021.001
T1021.001
T1562
T1562
T1059
T1059
T1547
T1547
T1203
T1203
Victims(200)
| Company | Country | Status | Discovered | |
|---|---|---|---|---|
| Vista Plastic Solutions | United States | Claimed | about 3 hours ago | |
| Inglewood Golf and Curling Club | Canada | Claimed | about 3 hours ago | |
| Barrett Mahony Consulting Engineers Ltd | Ireland | Claimed | about 3 hours ago | |
| Sys-Kool, LLC | United States | Claimed | 8 days ago | |
| Grunthal Welding | Canada | Claimed | 8 days ago | |
| Red Star Oil Company | Serbia | Claimed | 10 days ago | |
| GT Distributors | United States | Claimed | 10 days ago | |
| Mobilier MEQ Ltée | Canada | Claimed | 18 days ago | |
| Figgins Family Wine Estates | United States | Claimed | 18 days ago | |
| KRC Machine Tool Solutions | United States | Claimed | 18 days ago | |
| Meteor | Germany | Claimed | 18 days ago | |
| Be Media | United States | Claimed | 29 days ago | |
| Latoplast Ltd. | Latvia | Claimed | 29 days ago | |
| Coltrane | United States | Claimed | about 1 month ago | |
| Bridgeport Capital | United States | Claimed | about 1 month ago | |
| Sam Pack Auto Group | United States | Claimed | about 1 month ago | |
| Woodhaven Lakes Association | United States | Claimed | about 1 month ago | |
| MIE Solutions | United Kingdom | Claimed | about 1 month ago | |
| Rilpa Enterprises | Canada | Claimed | about 1 month ago | |
| Marconi Industrial Services S.p.a. | Italy | Claimed | about 1 month ago |
Page 1 of 10
Affected countries(84)
Countries where this group has been reported to target or leak victims.