Actor · Closed · since 2022
Play: the closed group that phones its victims
Active since June 2022, Play had hit about 900 organizations by May 2025 per the FBI and is a top three ransomware threat to Canada. Access and controls.
- Model
- Closed group · since 2022-06
- Aliases
- Playcrypt
- Ways in
- Purchased valid accounts · Exposed RDP and VPN · FortiOS CVEs · Exchange ProxyNotShell CVEs · SimpleHelp CVE
- Targets
- Information technology · Professional services · Public sector · Critical infrastructure · ESXi
- Official advisories
- AA23-352A
By Sentrix · Published 2026-09-20
Play makes no noise on criminal forums and does not recruit affiliates in the open. It exploits vulnerabilities that are several years old, steals the data, encrypts, then picks up the phone.
Who they are
Joint advisory AA23-352A from the FBI, CISA and the Australian Signals Directorate, published on December 18, 2023 and updated on June 4, 2025, dates the start of Play, also known as Playcrypt, to June 2022, with victims in North America, South America and Europe. As of May 2025, according to the same advisory, the FBI was aware of approximately 900 affected entities. The advisory presumes a closed group, designed to guarantee the secrecy of deals, which Unit 42 confirmed in October 2024 by quoting the group's leak site, which states it does not provide a RaaS ecosystem.
The Canadian Centre for Cyber Security, in its 2025-2027 outlook of January 28, 2026, reads it differently: Play emerged in June 2022 as a closed group and shifted to a RaaS model in November 2023. The same report lists it among the top three ransomware threats to Canada in 2024, with Akira and Medusa, and notes victims in the information technology and professional services sectors in Canada.
One rare fact sets Play apart: on October 30, 2024, Unit 42 assessed with moderate confidence a collaboration between Play and Jumpy Pisces, a North Korean state-sponsored group, acting as an initial access broker or affiliate in an intrusion that ran from May to September 2024.
How they get in
Advisory AA23-352A describes three families of initial access: valid accounts, often bought on criminal markets; exposed RDP and VPN services; and known vulnerabilities on edge devices, FortiOS CVE-2018-13379 and CVE-2020-12812, Microsoft Exchange ProxyNotShell CVE-2022-41040 and CVE-2022-41082, and since January 2025 the SimpleHelp remote management tool through CVE-2024-57727. Check Point adds exposed RDP servers as a recurring vector.
Inside, the group uses AdFind, Mimikatz, Cobalt Strike and PsExec, then exfiltrates with WinRAR and WinSCP before encrypting, according to the advisory. Encryption is hybrid AES and RSA, intermittent for speed, with the .PLAY extension, and an ESXi variant powers off virtual machines before encrypting their files. The ransom note provides a unique address at gmx.de or web.de; a portion of victims then get a phone call threatening to publish the data.
What they have done
- Late 2022: attack on the judiciary of Córdoba, Argentina, reported by Check Point.
- May 2023: data theft affecting the Swiss federal administration through a supplier, with 1.3 million confidential records according to Check Point.
- May to September 2024: intrusion from a compromised user account, with the Sliver and DTrack tools, attributed by Unit 42 to Jumpy Pisces and concluded by the deployment of Play in early September 2024.
- January 2025: exploitation of CVE-2024-57727 on SimpleHelp to enter US organizations, added to advisory AA23-352A in its June 2025 update.
What stops them
The mitigations of advisory AA23-352A, in the order in which they cut the attack chain.
- Patch edge devices and remote management tools first: FortiOS, Exchange, SimpleHelp. A years-old patch never applied is still an open door. ISO 27001:2022 A.8.8, SOC 2 CC7.1.
- MFA on webmail, VPN and privileged accounts, because valid accounts open most intrusions. ISO 27001:2022 A.8.5, SOC 2 CC6.1.
- Take RDP off the internet and go through a monitored gateway or jump host. ISO 27001:2022 A.8.20 and A.8.22.
- Recovery plan and tested offline backups, with copies for ESXi. ISO 27001:2022 A.8.13 and A.5.30, SOC 2 A1.2.
- Detection of common attack tools: AdFind, Mimikatz, Cobalt Strike and PsExec flagged by EDR before encryption. ISO 27001:2022 A.8.16, SOC 2 CC7.2.
- A procedure for extortion calls: who answers, who decides, who talks to law enforcement. ISO 27001:2022 A.5.24 to A.5.26.
Sources
- CISA, FBI, ASD, #StopRansomware: Play Ransomware, AA23-352A (December 18, 2023, updated June 4, 2025)
- Canadian Centre for Cyber Security, Ransomware Threat Outlook 2025-2027 (January 28, 2026)
- Check Point, Play Ransomware Group: Detection and Protection
- Palo Alto Networks Unit 42, Jumpy Pisces Engages in Play Ransomware (October 30, 2024)
Frequently asked questions
- Is Play a RaaS or a closed group?
- Sources disagree. Advisory AA23-352A presumes a closed group, designed to guarantee the secrecy of deals, and Unit 42 reports that the Play leak site states it does not provide a RaaS ecosystem. The Canadian Centre for Cyber Security writes instead that Play, which emerged as a closed group, shifted to a RaaS model in November 2023. Either way, the intrusion playbook stays the same.
- Why is Play known for phone calls?
- Advisory AA23-352A describes extortion without a negotiation portal: each victim receives a unique email address at gmx.de or web.de in the ransom note, and a portion of victims are then contacted by telephone and threatened with the release of the stolen data. It is a useful distinguishing sign for identifying the group in the first hours of an incident.
- Which entry points does Play exploit?
- According to advisory AA23-352A, valid accounts bought on criminal markets, exposed RDP and VPN services, and known vulnerabilities: FortiOS CVE-2018-13379 and CVE-2020-12812, Exchange ProxyNotShell CVE-2022-41040 and CVE-2022-41082, and since January 2025 the SimpleHelp remote management tool through CVE-2024-57727. These are old patches that many teams never applied.
Let's talk about your compliance program.
Last updated: 2026-09-20
