ZeroFox Intelligence Flash Report - Play Ransomware Increases Activity
|by Alpha Team

ZeroFox Intelligence Flash Report - Play Ransomware Increases Activity
Product Serial: F-2023-11-22a
TLP:CLEAR
In this flash report, ZeroFox researchers report on an increased operational activity of Play ransomware in Q4 2023.
Standing Intelligence Requirements
Deep Dark Web and Criminal Underground

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- Financially-motivated ransomware collective Play has increased the cadence of its operational activity in Q4 2023, having been responsible for approximately 14 percent of all ransomware and digital extortion (R&DE) activity observed by ZeroFox in October.
- Play is increasingly targeting organizations based in North America, which comprised 74 percent of all victims in October 2023. This is in stark contrast to just 35 percent of victims being from this region between Q2 2022 and Q3 2023.
- There is a roughly even chance that this increased operational tempo is due in part to a recent shift by Play to an as-a-service model, whereby affiliates are able to purchase the software or lease it via a subscription-based model. This would see associated activity increase, particularly if the services are made available to threat groups and individuals of lower sophistication.
Tags: tlp:clear, threat actor, all industries, DDW Ransomware