LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G1040: Play

Play is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a double-extortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.[1][2]

EnterpriseG1040GroupObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Play is documented by ATT&CK as a ransomware group active since at least 2022 that uses Playcrypt and a double-extortion model: data theft followed by encryption. The business significance is not just malware execution; the related ATT&CK context points to credential abuse, Active Directory discovery, lateral movement over SMB/admin mechanisms, exfiltration, and cleanup behaviors that can turn one compromised account or host into an enterprise-wide outage and data disclosure event.

Executive priority

Treat this as a resilience and identity-risk scenario, not only an endpoint malware scenario. Leaders should ask whether the organization can prove coverage for credential dumping, privileged/domain account misuse, AD reconnaissance, lateral movement, unusual egress, and ransomware recovery. Because ATT&CK cites impacts across business, government, critical infrastructure, healthcare, and media sectors in the Americas and Europe, the relevant executive decision is whether incident response, legal/compliance, backup restoration, and data-exposure processes are exercised before encryption and extortion force time-critical decisions.

Technical view

ATT&CK does not provide a dedicated detection section, platforms, or tactics for the Play group object. However, the relationship set is operationally useful: Play is associated with Playcrypt, Mimikatz, PsExec, Cobalt Strike, Empire, BloodHound, AdFind, Nltest, Wevtutil, LSASS memory access, valid accounts, domain/local account abuse, PowerShell, Windows command shell, SMB/admin shares, discovery, exfiltration over alternate protocols, data transfer size limits, and file deletion. SOC and IR teams should validate whether they can correlate these behaviors across identity, endpoint, directory, network, and backup/restore evidence rather than relying on a single ransomware signature.

Likely telemetry

  • Endpoint process creation and command-line telemetry for PowerShell, cmd, PsExec-like execution, Nltest, AdFind, BloodHound, Wevtutil, and other administrative utilities
  • Windows security and endpoint events indicating LSASS access, credential dumping attempts, suspicious handle access, or memory access patterns
  • Active Directory and identity provider logs for domain account use, local/domain admin activity, unusual authentication, privilege use, and lateral logons
  • SMB and Windows admin share access logs, remote service execution evidence, and host-to-host connection records
  • Network flow, proxy, DNS, firewall, and egress logs capable of showing alternate-protocol exfiltration and unusual transfer sizing

Detection direction

  • Build detections around behavior chains: credential access or valid-account abuse followed by AD discovery, remote system discovery, SMB/admin share movement, exfiltration, and encryption-like file activity.
  • Tune dual-use tool alerts carefully. PsExec, Nltest, AdFind, BloodHound, Wevtutil, PowerShell, and cmd can be legitimate; prioritize rare users, rare hosts, unusual parent processes, off-hours use, and execution from non-administrative workstations or servers.
  • Validate LSASS monitoring and credential-theft controls with safe internal tests, because credential capture can precede lateral movement and make later activity appear as legitimate account use.
  • Correlate identity and endpoint telemetry. Valid account use may bypass malware-centric controls, so detections should include impossible or unusual logon paths, abnormal admin share use, and new host-to-host access patterns.
  • Check egress monitoring for low-and-slow or chunked transfers, because the related exfiltration technique includes data transfer size limits that may avoid simple volume-threshold alerts.

Mitigation priorities

  • Prioritize identity hardening: reduce standing privilege, review domain and local administrator exposure, protect service accounts, and require strong controls for remote access and privileged activity.
  • Harden Windows/AD administration paths associated with the relationship context: restrict SMB/admin share exposure, control remote execution tooling, and maintain an approved-admin-tool baseline.
  • Reduce credential theft impact through credential protection, administrative tiering, limiting interactive logons for privileged accounts, and rapid credential reset procedures during incidents.
  • Improve egress governance by monitoring and restricting unexpected outbound protocols and destinations, especially from servers and sensitive data stores.
  • Prepare ransomware recovery evidence: offline or immutable backups, restoration testing, segmentation validation, and documented decisions for containment, data exposure, legal notification, and executive escalation.
Additional notes and limits

This take is based on the ATT&CK group description, external references listed for the object, and supplied relationships. The most decision-relevant relationships are the combination of credential access, valid account abuse, AD discovery tools, remote execution/lateral movement, exfiltration behaviors, file deletion, and Playcrypt ransomware use. Defensive validation should focus on whether these behaviors can be observed and correlated in the local environment.

The supplied Play group object has no official detection text, no group-level platforms, and no group-level tactics. Relationship data provides useful context but does not prove every behavior occurs in every incident. Local telemetry, asset criticality, identity architecture, backup design, and incident evidence are required to determine actual exposure or coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Play

Play is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a double-extortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.[1][2]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

26 rows
DomainIDNameRelationship / procedure
EnterpriseT1030Data Transfer Size Limits

Play has split victims' files into chunks for exfiltration.[1][2]

EnterpriseT1016System Network Configuration Discovery

Play has used the information-stealing tool Grixba to enumerate network information.[1]

EnterpriseT1048Exfiltration Over Alternative Protocol

Play has used WinSCP to exfiltrate data to actor-controlled accounts.[1][2]

EnterpriseT1070.004File DeletionSub-technique

Play has used tools including Wevtutil to remove malicious files from compromised hosts.[2]

EnterpriseT1059.003Windows Command ShellSub-technique

Play has used a batch script to remove indicators of its presence on compromised hosts.[2]

EnterpriseT1059.001PowerShellSub-technique

Play has used Base64-encoded PowerShell scripts to disable Microsoft Defender.[2]

EnterpriseT1560.001Archive via UtilitySub-technique

Play has used WinRAR to compress files prior to exfiltration.[1][2]

EnterpriseT1018Remote System Discovery

Play has used tools such as AdFind, Nltest, and BloodHound to enumerate shares and hostnames on compromised networks.[2]

EnterpriseT1057Process Discovery

Play has used the information stealer Grixba to check for a list of security processes.[2]

EnterpriseT1027.010Command ObfuscationSub-technique

Play has used Base64-encoded PowerShell scripts for post exploit activities on compromised hosts.[2]

EnterpriseT1587.001MalwareSub-technique

Play developed and employ Playcrypt ransomware.[2][1]

EnterpriseT1078.003Local AccountsSub-technique

Play has used valid local accounts to gain initial access.[2]

EnterpriseT1021.002SMB/Windows Admin SharesSub-technique

Play has used Cobalt Strike to move laterally via SMB.[2]

EnterpriseT1685.005Clear Windows Event LogsSub-technique

Play has used tools to remove log files on targeted systems.[1][2]

EnterpriseT1078Valid Accounts

Play has used valid VPN accounts to achieve initial access.[1]

EnterpriseT1105Ingress Tool Transfer

Play has used Cobalt Strike to download files to compromised machines.[2]

EnterpriseT1078.002Domain AccountsSub-technique

Play has used valid domain accounts for access.[2]

EnterpriseT1082System Information Discovery

Play has leveraged tools to enumerate system information.[2]

EnterpriseT1083File and Directory Discovery

Play has used the Grixba information stealer to list security files and processes.[2]

EnterpriseT1518.001Security Software DiscoverySub-technique

Play has used the information-stealing tool Grixba to scan for anti-virus software.[1]

EnterpriseT1133External Remote Services

Play has used Remote Desktop Protocol (RDP) and Virtual Private Networks (VPN) for initial access.[1][2]

EnterpriseT1588.002ToolSub-technique

Play has used multiple tools for discovery and defense evasion purposes on compromised hosts.[1]

EnterpriseT1190Exploit Public-Facing Application

Play has exploited known vulnerabilities for initial access including CVE-2018-13379 and CVE-2020-12812 in FortiOS and CVE-2022-41082 and CVE-2022-41040 ("ProxyNotShell") in Microsoft Exchange.[1][2]

EnterpriseT1003.001LSASS MemorySub-technique

Play has used Mimikatz and the Windows Task Manager to dump LSASS process memory.[2]

EnterpriseT1657Financial Theft

Play demands ransom payments from victims to unencrypt filesystems and to not publish sensitive data exfiltrated from victim networks.[1]

EnterpriseT1685Disable or Modify Tools

Play has used tools including GMER, IOBit, and PowerTool to disable antivirus software.[1][2]

Associated objects

Groups, software, and campaigns

ToolEnterprise

S0359: Nltest

Nltest is a Windows command-line utility used to list domain controllers and enumerate domain trusts.[1]

Windows
ToolEnterprise

S0029: PsExec

PsExec is a free Microsoft tool that can be used to execute a program on another computer. It is used by IT administrators and attackers.[1][2]

Windows
ToolEnterprise

S0363: Empire

Empire is an open-source, cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python, the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries.[1][2][3]

LinuxmacOSWindows
ToolEnterprise

S0645: Wevtutil

Wevtutil is a Windows command-line utility that enables administrators to retrieve information about event logs and publishers.[1]

Windows
MalwareEnterprise

S0154: Cobalt Strike

Cobalt Strike is a commercial, full-featured, remote access tool that bills itself as “adversary simulation software designed to execute targeted attacks and emulate the post-exploitation actions of advanced threat actors”. Cobalt Strike’s interactive post-exploit capabilities cover the full range of ATT&CK tactics, all executed within a single, integrated system.[1]

In addition to its own capabilities, Cobalt Strike leverages the capabilities of other well-known tools such as Metasploit and Mimikatz.[1]

LinuxmacOSWindows
MalwareEnterprise

S1162: Playcrypt

Playcrypt is a ransomware that has been used by Play since at least 2022 in attacks against against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Playcrypt derives its name from adding the .play extension to encrypted files and has overlap with tactics and tools associated with Hive and Nokoyawa ransomware and infrastructure associated with Quantum ransomware.[1][2][3]

Windows
ToolEnterprise

S0002: Mimikatz

Mimikatz is a credential dumper capable of obtaining plaintext Windows account logins and passwords, along with many other features that make it useful for testing the security of networks. [1] [2]

Windows
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.0
Created
Modified
Raw hash
0bd42175ffe5f4b0...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.0Current bundle0bd42175ffe5…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    CISA Play Ransomware Advisory December 2023

    CISA. (2023, December 18). #StopRansomware: Play Ransomware AA23-352A. Retrieved September 24, 2024.

    Open source URL
  2. [2]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  3. [3]
    CISA Play Ransomware Advisory December 2023

    CISA. (2023, December 18). #StopRansomware: Play Ransomware AA23-352A. Retrieved September 24, 2024.

    Open source URL
  4. [4]
    CISA Play Ransomware Advisory December 2023

    CISA. (2023, December 18). #StopRansomware: Play Ransomware AA23-352A. Retrieved September 24, 2024.

    Open source URL
  5. [5]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  6. [6]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  7. [7]
    mitre-attackG1040
    Open source URL
  8. [8]
    mitre-attackG1040
    Open source URL
  9. [9]
    mitre-attackG1040
    Open source URL
  10. [10]
    CISA Play Ransomware Advisory December 2023

    CISA. (2023, December 18). #StopRansomware: Play Ransomware AA23-352A. Retrieved September 24, 2024.

    Open source URL
  11. [11]
    CISA Play Ransomware Advisory December 2023

    CISA. (2023, December 18). #StopRansomware: Play Ransomware AA23-352A. Retrieved September 24, 2024.

    Open source URL
  12. [12]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  13. [13]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  14. [14]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  15. [15]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  16. [16]
    CISA Play Ransomware Advisory December 2023

    CISA. (2023, December 18). #StopRansomware: Play Ransomware AA23-352A. Retrieved September 24, 2024.

    Open source URL
  17. [17]
    CISA Play Ransomware Advisory December 2023

    CISA. (2023, December 18). #StopRansomware: Play Ransomware AA23-352A. Retrieved September 24, 2024.

    Open source URL
  18. [18]
    CISA Play Ransomware Advisory December 2023

    CISA. (2023, December 18). #StopRansomware: Play Ransomware AA23-352A. Retrieved September 24, 2024.

    Open source URL
  19. [19]
    CISA Play Ransomware Advisory December 2023

    CISA. (2023, December 18). #StopRansomware: Play Ransomware AA23-352A. Retrieved September 24, 2024.

    Open source URL
  20. [20]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  21. [21]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  22. [22]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  23. [23]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  24. [24]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  25. [25]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  26. [26]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  27. [27]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  28. [28]
    CISA Play Ransomware Advisory December 2023

    CISA. (2023, December 18). #StopRansomware: Play Ransomware AA23-352A. Retrieved September 24, 2024.

    Open source URL
  29. [29]
    CISA Play Ransomware Advisory December 2023

    CISA. (2023, December 18). #StopRansomware: Play Ransomware AA23-352A. Retrieved September 24, 2024.

    Open source URL
  30. [30]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  31. [31]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  32. [32]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  33. [33]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  34. [34]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  35. [35]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  36. [36]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  37. [37]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  38. [38]
    CISA Play Ransomware Advisory December 2023

    CISA. (2023, December 18). #StopRansomware: Play Ransomware AA23-352A. Retrieved September 24, 2024.

    Open source URL
  39. [39]
    CISA Play Ransomware Advisory December 2023

    CISA. (2023, December 18). #StopRansomware: Play Ransomware AA23-352A. Retrieved September 24, 2024.

    Open source URL
  40. [40]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  41. [41]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  42. [42]
    CISA Play Ransomware Advisory December 2023

    CISA. (2023, December 18). #StopRansomware: Play Ransomware AA23-352A. Retrieved September 24, 2024.

    Open source URL
  43. [43]
    CISA Play Ransomware Advisory December 2023

    CISA. (2023, December 18). #StopRansomware: Play Ransomware AA23-352A. Retrieved September 24, 2024.

    Open source URL
  44. [44]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  45. [45]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  46. [46]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  47. [47]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  48. [48]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  49. [49]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  50. [50]
    CISA Play Ransomware Advisory December 2023

    CISA. (2023, December 18). #StopRansomware: Play Ransomware AA23-352A. Retrieved September 24, 2024.

    Open source URL
  51. [51]
    CISA Play Ransomware Advisory December 2023

    CISA. (2023, December 18). #StopRansomware: Play Ransomware AA23-352A. Retrieved September 24, 2024.

    Open source URL
  52. [52]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  53. [53]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  54. [54]
    CISA Play Ransomware Advisory December 2023

    CISA. (2023, December 18). #StopRansomware: Play Ransomware AA23-352A. Retrieved September 24, 2024.

    Open source URL
  55. [55]
    CISA Play Ransomware Advisory December 2023

    CISA. (2023, December 18). #StopRansomware: Play Ransomware AA23-352A. Retrieved September 24, 2024.

    Open source URL
  56. [56]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  57. [57]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  58. [58]
    CISA Play Ransomware Advisory December 2023

    CISA. (2023, December 18). #StopRansomware: Play Ransomware AA23-352A. Retrieved September 24, 2024.

    Open source URL
  59. [59]
    CISA Play Ransomware Advisory December 2023

    CISA. (2023, December 18). #StopRansomware: Play Ransomware AA23-352A. Retrieved September 24, 2024.

    Open source URL
  60. [60]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  61. [61]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  62. [62]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  63. [63]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  64. [64]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  65. [65]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  66. [66]
    CISA Play Ransomware Advisory December 2023

    CISA. (2023, December 18). #StopRansomware: Play Ransomware AA23-352A. Retrieved September 24, 2024.

    Open source URL
  67. [67]
    CISA Play Ransomware Advisory December 2023

    CISA. (2023, December 18). #StopRansomware: Play Ransomware AA23-352A. Retrieved September 24, 2024.

    Open source URL
  68. [68]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  69. [69]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  70. [70]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  71. [71]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  72. [72]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  73. [73]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  74. [74]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  75. [75]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  76. [76]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  77. [77]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  78. [78]
    CISA Play Ransomware Advisory December 2023

    CISA. (2023, December 18). #StopRansomware: Play Ransomware AA23-352A. Retrieved September 24, 2024.

    Open source URL
  79. [79]
    CISA Play Ransomware Advisory December 2023

    CISA. (2023, December 18). #StopRansomware: Play Ransomware AA23-352A. Retrieved September 24, 2024.

    Open source URL
  80. [80]
    CISA Play Ransomware Advisory December 2023

    CISA. (2023, December 18). #StopRansomware: Play Ransomware AA23-352A. Retrieved September 24, 2024.

    Open source URL
  81. [81]
    CISA Play Ransomware Advisory December 2023

    CISA. (2023, December 18). #StopRansomware: Play Ransomware AA23-352A. Retrieved September 24, 2024.

    Open source URL
  82. [82]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  83. [83]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  84. [84]
    CISA Play Ransomware Advisory December 2023

    CISA. (2023, December 18). #StopRansomware: Play Ransomware AA23-352A. Retrieved September 24, 2024.

    Open source URL
  85. [85]
    CISA Play Ransomware Advisory December 2023

    CISA. (2023, December 18). #StopRansomware: Play Ransomware AA23-352A. Retrieved September 24, 2024.

    Open source URL
  86. [86]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  87. [87]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  88. [88]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  89. [89]
    CISA Play Ransomware Advisory December 2023

    CISA. (2023, December 18). #StopRansomware: Play Ransomware AA23-352A. Retrieved September 24, 2024.

    Open source URL
  90. [90]
    CISA Play Ransomware Advisory December 2023

    CISA. (2023, December 18). #StopRansomware: Play Ransomware AA23-352A. Retrieved September 24, 2024.

    Open source URL
  91. [91]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.