Playcrypt

MITRE
Malware Type:
Other
First seen:
Unknown
Last seen:
Unknown
Details:

[Playcrypt](https://attack.mitre.org/software/S1162) is a ransomware that has been used by [Play](https://attack.mitre.org/groups/G1040) since at least 2022 in attacks against against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. [Playcrypt](https://attack.mitre.org/software/S1162) derives its name from adding the .play extension to encrypted files and has overlap with tactics and tools associated with Hive and Nokoyawa ransomware and infrastructure associated with Quantum ransomware.(Citation: Microsoft PlayCrypt August 2022)(Citation: CISA Play Ransomware Advisory December 2023)(Citation: Trend Micro Ransomware Spotlight Play July 2023)

Associated Techniques (3)
ID ATT&CK Tactics
T1083 File and Directory Discovery -
T1486 Data Encrypted for Impact -
T1490 Inhibit System Recovery -
Aliases (105)
Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play Play
Used by Actors (1)
Metadata
ID: 100
Created: 13/01/2026 17:48
Updated: 06/03/2026 16:00