White Paper
THREAT PROFILE: Play Ransomware
Play Ransomware is a cybercriminal group first identified in 2022 and is widely associated with ransomware operations, although there is debate over whether it functions as a ransomware-as-a-service (RaaS) platform or a private organization. The group employs a double-extortion strategy, encrypting victims’ systems while simultaneously stealing sensitive data and threatening to publish it on a dedicated leak site if ransom demands are not met. This threat profile examines Play Ransomware’s tactics, techniques, and procedures, including its targeted industries and regions, exploited vulnerabilities, known tools, and associations with other threat actors. The report also analyzes observed attack behaviors in Windows environments, maps activities to the MITRE ATT&CK framework, and outlines th
