Home/Threat Actor/Play
Threat Actor

Play

play_ransomware · russia_aligned_cybercrime · active since 2022

Play (Playcrypt / Balloonfly / G1040) is one of the more operationally consequential ransomware operations of the 2022- 2024 period, a financially-motivated organized cyber-criminal cluster operating from Russia and adjacent post-Soviet states emerging in June 2022, with documented compromise of 300+ organizations globally per CISA + FBI + ACSC + ASD joint cybersecurity advisory AA23-352A (December 18, 2023)

most operationally consequential cluster-tradecraft contribution the OWASSRF (Outlook Web Access Server-Side Request Forgery) Microsoft Exchange exploitation chain (CVE-2022-41080 + CVE-2022-41082) discovered during CrowdStrike incident response on the early-December-2022 Rackspace Technology Hosted Exchange attack, operationally consequential beyond Rackspace because Exchange environments worldwide were vulnerable pending the January 2023 Microsoft patch.

high-profile documented victims including Rackspace Technology Hosted Exchange (December 2022, thousands of customer email service disruption for multiple weeks), City of Oakland California (February 2023, weeks of city government IT disruption), Arnold Clark UK automotive retailer (December 2022 - January 2023), H-Hotels German hotel chain (December 2022), Belgian city of Antwerp (December 2022), A10 Networks (January 2023), Krispy Kreme (multiple 2023 incidents), Microchip Technology US semiconductor (August 2024); distinctive operational branding via .play file extension and minimalist "PLAY"-plus-contact-email ransom note style contrasting with verbose-marketing peer ransomware operations.

initial-access tradecraft centers on Microsoft Exchange exploitation via ProxyNotShell and OWASSRF, FortiOS SSL VPN exploitation (CVE-2018-13379 / CVE-2022-42475 / CVE-2023-27997), and RDP credential theft.

operationally unusual selective Ukrainian targeting pattern documented by Microsoft Threat Intelligence Center across 2022-2024 (operationally unusual among predominantly-Western-victim-focused ransomware operations, most of which avoid CIS-state targets including Ukraine) consistent with broader Russian state security service interests in targeting Ukrainian infrastructure during the ongoing Russia- Ukraine war, contributing to selective vendor analysis questioning whether Play maintains operational coordination with Russian state security service interests beyond pure financially- motivated cybercrime, though Play remains primarily financially- motivated cybercrime operationally.

russia_aligned_cybercrime confidence: high 13 aliases MITRE ATT&CK G1040 ↗

Profile

Play (also tracked as Playcrypt, Balloonfly [Microsoft], and MITRE ATT&CK G1040) is one of the more operationally consequential ransomware operations of the 2022-2024 period, a financially- motivated organized cyber-criminal cluster operating from Russia and adjacent post-Soviet states. The cluster emerged in June 2022 and represents one of the more sustained operationally- mature ransomware operations of the period with documented compromise of 300+ organizations globally per the CISA + FBI + Australian Cyber Security Centre + Australian Signals Directorate joint cybersecurity advisory AA23-352A (December 18, 2023). The cluster's distinctive operational branding is the .play file extension appended to encrypted files combined with a minimalist ransom note style (the word "PLAY" alone followed by a contact email address), operationally distinctive branding relative to verbose-ransom-note peer ransomware operations.

The branding choice contrasts with the verbose-marketing branding of many peer ransomware operations and reflects the cluster's operational positioning as understated rather than attention-seeking. The cluster's most operationally consequential cluster-tradecraft contribution was the OWASSRF (Outlook Web Access Server-Side Request Forgery) Microsoft Exchange exploitation chain discovered during CrowdStrike incident response on the early-December-2022 Rackspace Technology Hosted Exchange attack and disclosed in late December 2022. The OWASSRF chain combined CVE-2022-41080 and CVE-2022-41082 in a novel server-side-request-forgery-then- remote-code-execution attack against Microsoft Exchange environments.

The OWASSRF discovery was operationally consequential beyond the Rackspace incident because Exchange environments worldwide were vulnerable to the chain pending the eventual January 2023 Microsoft patch. The Rackspace incident itself disrupted email services for thousands of Rackspace Hosted Exchange customers across the US for multiple weeks. Operationally Play's initial-access tradecraft has centered on three primary patterns: First, Microsoft Exchange exploitation via ProxyNotShell (CVE-2022-41040 + CVE-2022-41082) and the OWASSRF chain (CVE-2022-41080 + CVE-2022-41082) across late 2022 and 2023.

Second, FortiOS SSL VPN exploitation including CVE-2018-13379, CVE-2022-42475, and CVE-2023-27997. The FortiOS-targeting tradecraft is consistent with broader contemporary cybercrime- cluster patterns of exploiting Fortinet, SonicWall, Cisco, and other VPN-and-perimeter-security-product vulnerabilities for initial access. Third, RDP credential theft and exploitation of internet-exposed RDP services.

The cluster operates Linux + ESXi ransomware variants alongside the Windows variant, consistent with broader contemporary cybercrime-cluster patterns of VMware ESXi hypervisor targeting for disproportionately high operational impact relative to deployment effort. An operationally unusual cluster signature is the selective Ukrainian targeting pattern documented across 2022-2024. Microsoft Threat Intelligence Center has tracked Play ransomware deployments against Ukrainian organizations including selected Ukrainian government and commercial entities.

The Ukrainian- targeting pattern is operationally unusual among predominantly- Western-victim-focused ransomware operations, most major ransomware operations explicitly avoid Russia, Belarus, and CIS-state targets including Ukraine, and is consistent with broader Russian state security service interests in targeting Ukrainian infrastructure during the ongoing Russia-Ukraine war. The pattern has contributed to selective vendor analysis questioning whether Play maintains operational coordination with Russian state security service interests beyond pure financially- motivated cybercrime, though Play remains primarily financially- motivated cybercrime operationally and the Ukrainian-targeting pattern represents a small fraction of overall cluster operational volume.

High-profile documented Play victims include Rackspace Technology Hosted Exchange (December 2022), City of Oakland California (February 2023), Arnold Clark UK automotive retailer (December 2022
  • January 2023), H-Hotels German hotel chain (December 2022), Belgian city of Antwerp (December 2022), A10 Networks (January 2023), Krispy Kreme (multiple 2023 incidents), Microchip Technology US semiconductor (August 2024), and hundreds of additional commercial and government-sector targets. A handful of operational notes: First, the cluster represents one of the more sustained operationally-mature ransomware operations of the 2022-2024 period with consistent operational tempo and continued capability development across the operational lifespan. The 300+ documented victims and the diversity of high-profile incidents (Rackspace Exchange supply-chain impact, City of Oakland municipal government, Belgian Antwerp city government, Arnold Clark UK automotive supply-chain disruption) demonstrate substantial operational impact. Second, the OWASSRF Exchange exploitation chain discovery during the December 2022 Rackspace incident response represents one of the more operationally consequential contemporary cybercrime- cluster contributions to the broader threat-intelligence community vulnerability-research understanding. The pattern of financially-motivated cluster operations driving discovery of enterprise-infrastructure vulnerability chains (rather than vulnerability-disclosure preceding cluster exploitation) is operationally significant. Third, the selective Ukrainian targeting pattern represents one of the more analytically interesting elements of the cluster profile. The pattern complements the broader analytical framing applied to Wizard Spider / Conti (ContiLeaks-revealed apparent intelligence-service-adjacent contacts), Indrik Spider / Evil Corp (OFAC explicit Russian FSB tasking allegation), and Black Basta (BlackBastaLeaks-revealed apparent connections) where elements of the Russia-speaking organized cybercrime ecosystem maintain operational coordination with Russian state security service interests. The cumulative pattern across multiple clusters supports the broader gray-zone analytical framing for the Russia-speaking organized-cybercrime-and-state-security- services intersection. Fourth, no formal individual-operator attribution at the named- Russian-national tier has been publicly issued for Play administrators, consistent with the broader pattern of absence of similar named-individual-attribution for Cl0p, ALPHV / BlackCat, Black Basta, and Akira. Only LockBit (Khoroshev), Evil Corp (Yakubets / Turashev), and FIN7 (Dunaev / Hladyr / Kolpakov / Witte) have received named-Russian-national-tier formal attribution among the major contemporary cybercrime clusters covered in this corpus.

Aliases

13
playplay ransomwareplay_ransomwareplayransomwareplaycryptplay cryptplay_cryptballoonflyballoon flyballoon_flyg1040atk 256atk256

Notable Campaigns

9
2024-2025Continued Operations (2024-2025)
2023-2024FortiOS SSL VPN Exploitation (2023-2024)
2023-2024Additional High-Profile Victims (2023-2024)
2023City of Oakland California Attack (February 2023)
2023CISA + FBI + ACSC + ASD AA23-352A Play Cybersecurity Advisory (December 18, 2023)
2022-2024Selective Ukrainian Targeting Pattern (2022-2024)
2022-2023ProxyNotShell + OWASSRF Microsoft Exchange Exploitation (Late 2022 - 2023)
2022Play Ransomware Emergence (June 2022)
2022Rackspace Technology Hosted Exchange Attack (December 2022)

Attribution & Reporting

Attributed by
FBI Cyber DivisionCISA (US Cybersecurity and Infrastructure Security Agency)Australian Cyber Security Centre (ACSC)Australian Signals Directorate (ASD)Mandiant / Google Cloud Threat IntelligenceMicrosoft Threat Intelligence CenterCrowdStrikeRecorded Future Insikt GroupSentinelOneSophosTrend MicroKaspersky GReATGroup-IBPRODAFTCybereasonIBM X-ForceTrustwave SpiderLabsTrellixDFIR ReportCovewareHalcyonPalo Alto Networks Unit 42Symantec (Broadcom)AdluminCisco Talos
Key reporting
reportCISA + FBI + ACSC + ASD: AA23-352A #StopRansomware Play Ransomware Joint Cybersecurity Advisory (December 18, 2023), most operationally significant international government formal public attribution
reportCrowdStrike: OWASSRF Exploit Analysis and Recommendations (December 20, 2022), seminal OWASSRF discovery during Rackspace incident response
reportMicrosoft Threat Intelligence: Balloonfly / Play Ransomware Tracking (May 2023), selective Ukrainian targeting documentation
reportSymantec (Broadcom): Play Ransomware Initial Discovery and Continued Tracking
reportMandiant: Playcrypt Ransomware Continued Tracking
reportCisco Talos: Play Ransomware Deep Dive
reportSophos: Play Ransomware Operational Profile
reportTrend Micro: Ransomware Spotlight Play (November 2022)
reportPalo Alto Networks Unit 42: Play Ransomware Spider Stash (April 2023)
reportRecorded Future Insikt Group: Play Ransomware Tracking (multiple years)
reportAdlumin: Play Ransomware Tracking Incident Response Data
reportCoveware: Play Ransomware Tracking
reportHalcyon: Play Operational Profile
reportPRODAFT: Play Detailed Operational Analysis
reportGroup-IB: Play Continued Tracking
reportSophos: Play Continued Tracking
reportDFIR Report: Play Operational Analysis
reportGuidePoint Security: Play Incident Response Tracking
reportMalpedia Actor Profile: Play
reportMITRE ATT&CK Group G1040, Play

Operational

State sponsor

Play (also tracked as Playcrypt, Balloonfly, and MITRE ATT&CK G1040) is a financially-motivated organized cyber-criminal cluster, not a state-aligned cluster, operating from Russia and adjacent post-Soviet states. The cluster has been associated with apparent operational coordination with Russian state security service interests in selected vendor analysis, similar to the broader analytical framing applied to Wizard Spider / Conti, Indrik Spider / Evil Corp, and Black Basta in this corpus, though formal explicit OFAC-style allegations of state security service tasking have not been publicly issued against Play administrators. The cluster emerged in June 2022 and represents one of the more operationally consequential ransomware operations of the 2022-2024 period with documented compromise of 300+ organizations globally per the CISA + FBI + Australian Cyber Security Centre joint cybersecurity advisory AA23-352A (December 18, 2023).

The cluster's selective vendor tracking has identified ongoing apparent state security service adjacencies, notably Microsoft Threat Intelligence Center's tracking of selective Play ransomware deployment against Ukrainian organizations during 2022-2024 (operationally unusual among predominantly-Western-victim-focused ransomware operations and consistent with broader Russian state security service interests in targeting Ukrainian infrastructure during the ongoing Russia-Ukraine war), though Play remains primarily financially-motivated cybercrime operationally. No formal individual-operator attribution at the named-Russian-national tier has been publicly issued for Play administrators.

Motivations
financial_gain, financially_motivated, cybercrime, ransomware_deployment, extortion, double_extortion, data_theft_for_extortion, ransomware_as_a_service_operations, selective_ukrainian_targeting_potentially_state_aligned
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)57/60 · 95%
Analytics (MITRE CAR)30/60 · 50%
Runtime / container (Falco)8/60 · 13%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)16/60 · 26%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

2 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MEGA NZMETERPRETERMSHTASHARPHOUNDSPLASHTOP ABUSE
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin