Feds Issue Update on Play Ransomware as Group Accelerates Attacks
The healthcare industry is targeted by ransomware groups, one of which has been accelerating attacks. The Play ransomware group, aka Playcrypt, significantly increased its attacks in May, according to an updated joint cybersecurity advisory from the Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI).
The joint cybersecurity advisory was first published in December 2023 and was updated this month with further information on the evolving tactics of the group. The Play ransomware operation has been active since at least June 2022 and targets businesses and critical infrastructure entities globally, although the majority of victims are located in North and South America and Europe.
The group does not conduct as many attacks as some of the biggest players in the ransomware ecosystem, but usually ranks in the top five. When the joint cybersecurity advisory was first issued, the Play ransomware group was known to have conducted around 300 attacks, but by June 2025, that total had trebled to around 900 – a significant escalation, making Play one of the most active ransomware groups currently in operation.
The Play ransomware operation is believed to be a closed group, rather than a ransomware-as-a-service operation, which the authoring agencies say helps to “guarantee the secrecy of deals.” Like most other groups, Play engages in double extortion, exfiltrating sensitive data before encrypting files. Payment of the ransom is required to obtain the decryption keys and to prevent the stolen data from being leaked on its dark web data leak site. The FBI reports that Play often increases pressure on victims by contacting them via telephone and threatening them with data leaks.
Initial access is achieved in a variety of ways, including abuse of valid accounts, the credentials for which may be purchased on the dark web. Public-facing applications are also targeted, exploiting vulnerabilities such as FortiOS (CVE-2018-13379), MS Exchange (CVE-2022-41040 and CVE-2022-41082), and more recently, the Windows elevation of privilege vulnerability CVE-2025-29824 and the SimpleHelp remote code execution vulnerability CVE-2024-57727.
Play actors have been observed using tools such as Cobalt Strike, PSExec, Mimikatz, AdFind, Windows Privilege Escalation Awesome Scripts (WinPEAS), PowerShell scripts to disable Windows Defender, and GMER, IOBit, and PowerTool to disable anti-virus software. Play compresses files with tools such as WinRAR before data exfiltration, often using WinSCP for data transfers. The Grixba information stealer has been deployed by the group in some attacks. The group has a Windows encryptor and an ESXi variant, both of which are recompiled for each campaign to make detection more difficult.
The updated cybersecurity advisory shares the latest indicators of Compromise (IoCs), YARA rules, detailed information on the group’s tactics, techniques, and procedures, and recommended mitigations to help network defenders improve their defenses.
