Skip to main content
Play (Playcrypt): FortiOS + Exchange to Double Extortion operation cover
COMING SOONAdvancedPRO

Play (Playcrypt): FortiOS + Exchange to Double Extortion

Operators consistent with the Play ransomware group abuse a valid SSL-VPN account and exploit a published Exchange server, run AdFind and Grixba, disable the endpoint defenses, beacon out with Cobalt Strike and SystemBC, move laterally over RDP, archive Finance and HR data with WinRAR, and upload roughly 9.6 GB to a file-sharing service before deleting shadow copies and running an intermittent-encryption impact stage. Work the FortiGate edge, Exchange web logs, the endpoint process tree, the perimeter egress, and the extortion email to reconstruct the full double-extortion intrusion.

1h 45m
7 tasks
150 points
Pro

Launches in 4 days

Aug 11, 2026

Tuesday, August 11, 2026 at 9:00 AM

View Pro plans

Pro unlocks this operation at launch.

Training Tools

SIEMXDRFirewallEmail

What you'll investigate

7 objectives unlock when this operation goes live.

1Pin the way in
2Confirm the second door
3Catch the blinding
4Spot the quiet account
5Follow the data out
6Read the demand
7Name the impact technique

Be first when it launches

Create your account and grab Pro before launch. The moment this operation goes live on Aug 11, 2026, you can jump straight in.

Get Started Free