Play

Play — Threat Actor Profile | ObscureIQ
ObscureIQ Threat Intelligence · Actor Profile

PlayConfidence: High

Ransomware
Also known as: PlayCrypt

Motivation: Financial

1Attributed Breaches
HighAttribution Confidence
RansomwareActor Type

Overview

One of the most active operations globally, with reports of nearly 900 victim organizations by 2025 across the Americas and Europe, first seen June 2022 and using double extortion. Subject of CISA advisory AA23-352A (updated June 2025).

Tactics, Targeting & TTPs

Double extortion. Subject of CISA advisory AA23-352A (updated June 2025).

Source

Attribution draws on public threat-intelligence reporting · Established (multi-source). Primary source →

Were you exposed in one of these breaches?

Check your exposure privately, or request a tailored exposure audit.

Request Consultation