Description
Playcrypt is a ransomware family used by the Play threat actor since at least 2022 against business, government, critical infrastructure, healthcare, and media sectors across North America, South America, and Europe. It takes its name from the .play extension added to encrypted files, and researchers have noted overlaps with Hive and Nokoyawa ransomware as well as infrastructure shared with Quantum ransomware.
Stats
- First seen
- January 2023
- Last seen
- October 2026
Also known as
PlayPlayCrypt
MITRE ATT&CK techniques
3 techniques across 2 tactics.
Associated groups
Alert name variants
| Alert Name |
|---|
| Gen:Variant.Ransom.Play.10 |
| Gen:Variant.Ransom.Play.22 |
| Gen:Variant.Ransom.Play.24 |
| Gen:Variant.Ransom.Play.29 |
| Gen:Variant.Ransom.Play.9 |
| Win32.Ransomware.Play |
| Win32.Ransomware.PlayCrypt |
| Win64.Ransomware.Play |






