Uptime Hamster: 20d 23h 31mDeploy: 3 Aug 2026 06:56Updated: 2026-07-21
Logo del actor de amenaza Play

Play

0 incidentes 0 paises 0 sectores threat-actor Ultimo: -
Aliases: una reputación de actividad prolongada, arid gopher, arid viper, spyc23, APT BAHAMUT, bisonal, tonto, tontoteam, APT CYBERBIT, APT DARKCARACAL, apt-c-3, apt3, ups, APT HACKINGTEAM, Ke3chang, Mirage, Playful Dragon, Royal APT
Ver en IntelTracker → APTTrail →
Play is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a double-extortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.

Aliases del actor

una reputación de actividad prolongadaarid gopherarid viperspyc23APT BAHAMUTbisonaltontotontoteamAPT CYBERBITAPT DARKCARACALapt-c-3apt3upsAPT HACKINGTEAMKe3changMiragePlayful DragonRoyal APTVixen Pandaapt15APT PKPLUGBackdoorDiplomacyQuarianTurianAPT QUASARAPT SPACEPIRATESAPT TA2101

Actores similares

apt-bahamutactor · 1apt-camarodragonactor · 1apt-cyberbitactor · 1apt-darkcaracalactor · 1apt-dragonokactor · 1apt-hackingteamactor · 1apt-pkplugactor · 1apt-quasaractor · 1apt-sharppandaactor · 1apt-spacepiratesactor · 1

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
Repositoriounknowngithub.comRansomware Group: play
DLS / onionunknownj75o7xvvsm4lpsjhkjvb4wl2q6ajegvabe6oswthuaubbykk4xkzgpid.onionmarktsec
DLS / onionunknownk7kg3jqxang3wh7hnmaiokchk7qoebupfgoik6rha6mjpzwupwtj25yd.onionmarktsec
DLS / oniononlinembrlkbtq5jonaqkurjwmxftytyn2ethqvbxfu4rgjbkkknndqwae6byd.onionCTI.FYI
DLS / onionunknownk7kg3jqxang3wh7hnmaiokchk7qoebupfgoik6rha6mjpzwupwtj25yd.onionKuhnline
DLS / onionunknownmbrlkbtq5jonaqkurjwmxftytyn2ethqvbxfu4rgjbkkknndqwae6byd.onionKuhnline
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: playboy
DLS / leak siteunknownnitter.netIdo Cohen: Tracking the pulse of ransomware in 2026—these are the groups leading the global attack landscape right now: Qilin – 665 attacks The Gentleman – 453 attacks Akira – 290 attacks DragonForce – 245 attacks INC – 239 attacks Lockbit – 199 attacks Play – 154 attacks CLOP – 127 attacks NightSpire – 115 attacks CoinBase Cartel – 97 attacks Stay ahead of ransomware threats.
X/Twitterunknownx.comIdo Cohen: Stormous is back with increased activity. Recent victims have had their public websites defaced with a ransomware message displayed directly on the homepage—a pressure tactic sometimes used by ransomware groups to increase urgency and force negotiations. DarkFeed makes it easy to compare a ransomware group's leak site with the victim's public website in one place, helping analysts quickly identify attacks like these.
DLS / leak siteunknownnitter.netIdo Cohen: Stormous is back with increased activity. Recent victims have had their public websites defaced with a ransomware message displayed directly on the homepage—a pressure tactic sometimes used by ransomware groups to increase urgency and force negotiations. DarkFeed makes it easy to compare a ransomware group's leak site with the victim's public website in one place, helping analysts quickly identify attacks like these.
Repositoriounknowngithub.comBushidoUK ToolMatrix GroupProfiles: PLAY
Repositorioupgithub.comBushidoUK ToolMatrix CommunityReports: CR-016-PLAY-APR-2025
Webunknownwww.cisa.govOSINT
Repositorioupgithub.comBushidoUK ToolMatrix CommunityReports: CR-016-PLAY-APR-2025
X/Twitterupx.comBushidoUK ToolMatrix CommunityReports: CR-016-PLAY-APR-2025
DLS / leak siteuphijacklibs.netBushidoUK ToolMatrix CommunityReports: CR-016-PLAY-APR-2025
DLS / leak siteupwww.guidepointsecurity.comBushidoUK ToolMatrix CommunityReports: CR-016-PLAY-APR-2025
Forounknownwww.breachsense.complaytimemobile.com - RaidForums Data Breach
Forounknowngetbootstrap.complaytimemobile.com - RaidForums Data Breach
Forounknowngithub.complaytimemobile.com - RaidForums Data Breach
Forounknowngithub.complaytimemobile.com - RaidForums Data Breach
Forounknowngithub.complaytimemobile.com - RaidForums Data Breach
DLS / leak siteunknownduckduckgo.comThe DeBruler
DLS / leak siteunknownduckduckgo.comThe DeBruler
DLS / onionofflinembrlkbtq5jonaqkurjwmxftytyn2ethqvbxfu4rgjbkkknndqwae6byd.onionCTI.FYI
DLS / onionunknownipi4tiumgzjsym6pyuzrfqrtwskokxokqannmd6sa24shvr7x5kxdvqd.onionmarktsec
Webunknownattack.mitre.orgOSINT
Tipo
threat-actor
Pais origen
-
Motivacion
-
Impacto
-
Actualizado
2026-08-03