Play Ransomware is a financially motivated cybercriminal group that emerged in June 2022. Operating as a closed group rather than employing affiliates, Play aims to maintain secrecy during negotiations and differentiates itself through its use of intermittent encryption to evade detection. The group primarily focuses its attacks on large enterprises and critical infrastructure across North America, South America, and Europe. While its exact country of origin remains unconfirmed by official sources, some analysis assesses with high confidence that the group has ties to Russia, evidenced by its avoidance of targeting post-Soviet countries, observed language patterns, and similarities to confirmed Russian ransomware groups. The group is also known by the alias Playcrypt.