Japan

play

Initially observed in June 2022, the Play ransomware (a.k.a PlayCrypt) operates through double extortion, targeting numerous organizations in Latin America. Its Initial Access method is quite similar to other ransomwares, involving attacks such as Phishing, Exposed Services to the Internet, and Valid Account compromises.<br> <br> On April 19, 2023, the security company Symantec published two new tools developed by the Play group. These tools allow the malicious actor to…

First seen 2022-11-27 · Last seen 2026-08-31 · 4 Japan claims

Tactics: Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Stealth, Credential Access, Discovery, Lateral Movement, Collection, Exfiltration, Command and Control

Cached from ransomware.live. 2026-10-01 PT. Leak sites are not linked.

Aphase II

JP

Discovered: 2025-10-29 <span class="ransom-ago">(11mo ago)</span>

United States

www.aphaseii.com

Jamco Aerospace

JP

Discovered: 2025-08-07 <span class="ransom-ago">(14mo ago)</span>

United States

www.jamco-aerospace.com

Media Links

JP

Discovered: 2025-05-27 <span class="ransom-ago">(16mo ago)</span>

Japan

www.medialinks.com

ITO EN

JP

Discovered: 2024-12-06 <span class="ransom-ago">(22mo ago)</span>

Japan

itoen.co.jp