Sigma Watch is free and independent. If it saves you time, keep it running. ☕ Buy me a coffee
SigmaWatch
Ransomware

Play

Ransomware 10 detections found

Also known as: Playcrypt, PlayCrypt Ransomware, Play Ransomware Group

Play (deploying the Playcrypt encryptor) is a closed, non-advertised ransomware operation active since June 2022 that uses double extortion and intermittent encryption, frequently exploiting FortiOS, Exchange, Citrix, and remote-management-tool vulnerabilities (e.g., SimpleHelp CVE-2024-57727) for initial access. It has compromised an estimated 900+ organizations across North America, South America, and Europe, including critical infrastructure, and remains active with no major law-enforcement disruption as of September 2026; CISA/FBI updated their joint advisory in mid-2025 to reflect evolving TTPs.

Detection & eradication references

Curated links to authoritative sources — MITRE ATT&CK, CISA advisories, law-enforcement takedown announcements, and vendor threat-intel writeups — for removal, remediation, and further technical detail. Sigma Watch does not publish its own removal steps here, since malware behavior and tooling change too fast for a static write-up to stay reliably accurate.

Detection rules