
Play (Playcrypt): FortiOS + Exchange to Double Extortion
Operators consistent with the Play ransomware group abuse a valid SSL-VPN account and exploit a published Exchange server, run AdFind and Grixba, disable the endpoint defenses, beacon out with Cobalt Strike and SystemBC, move laterally over RDP, archive Finance and HR data with WinRAR, and upload roughly 9.6 GB to a file-sharing service before deleting shadow copies and running an intermittent-encryption impact stage. Work the FortiGate edge, Exchange web logs, the endpoint process tree, the perimeter egress, and the extortion email to reconstruct the full double-extortion intrusion.
Launches in 4 days
Tuesday, August 11, 2026 at 9:00 AM
Pro unlocks this operation at launch.
Training Tools
What you'll investigate
7 objectives unlock when this operation goes live.
Be first when it launches
Create your account and grab Pro before launch. The moment this operation goes live on Aug 11, 2026, you can jump straight in.
Get Started Free