
Play (Playcrypt): FortiOS + Exchange to Double Extortion
Operators consistent with the Play ransomware group abuse a valid SSL-VPN account and exploit a published Exchange server, run AdFind and Grixba, disable the endpoint defenses, beacon out with Cobalt Strike and SystemBC, move laterally over RDP, archive Finance and HR data with WinRAR, and upload roughly 9.6 GB to a file-sharing service before deleting shadow copies and running an intermittent-encryption impact stage. Work the FortiGate edge, Exchange web logs, the endpoint process tree, the perimeter egress, and the extortion email to reconstruct the full double-extortion intrusion.
Start this operation
Investigation Tasks
Complete each task by investigating alerts and submitting your findings.
Pin the way in
20Overnight, the perimeter saw a remote-access session that did not behave like a normal staff connection. Work the FortiGate edge and VPN authentication records and isolate the external address behind the SSL-VPN session that authenticated without the account's usual second factor.
Confirm the second door
20The same operator did not rely on the VPN alone, the published mail server was hit in parallel. Identify the internal host that was driven to spawn a shell from its web application after the Exchange backend was reached.
Catch the blinding
25Before going loud, the operator made sure the endpoint defenses would not get in the way. Examine the beachhead process tree and endpoint records and identify the privileged account that disabled protection and was later reused to move through the estate.
Spot the quiet account
20The crew left themselves a durable way back in using an account that should never be active. Identify the built-in Windows account that was re-enabled and added to Administrators on the domain controller.
Follow the data out
25The most important fact for the business is that data left the building before anything was locked. Reconstruct the egress from the file server and report the external address the stolen archives were uploaded to.
Read the demand
20Hours after the data left, the business received a message confirming the breach and setting terms. From the email evidence, identify the sender address the operators used to make contact.
Name the impact technique
15Only after the data had been stolen were the files locked, and they were locked in a way built for speed. Map the final encryption stage to its MITRE ATT&CK technique.
7 tasks · 145 points total
Training Tools
SIEM Console
Log analysis & SPL queries
XDR Console
Endpoint detection & response
Firewall Console
Network traffic analysis
Email Console
Email header & content analysis
Skills You'll Build
Complex multi-stage investigations. Realistic noise, ambiguous indicators, lateral movement.
Prerequisites
- Basic understanding of security alerts
- Experience with log analysis tools
- Familiarity with SIEM concepts
- Familiarity with XDR concepts
- Familiarity with Firewall concepts
- Familiarity with Email concepts
Ready to investigate?
More Operations
View allQilin: Veeam credential abuse to ESXi hypervisor encryption
A Qilin operator exploits a manufacturing firm's SSL-VPN edge, recovers stored credentials from an internet-facing backup server, steals a domain-admin token, self-propagates over SMB to vCenter, exfiltrates data over an encrypted tunnel, clears the Windows logs, and encrypts the ESXi datastores after mass-powering-off the guests. Work the FortiGate and Windows logs, the endpoint process tree, the perimeter traffic, and the vCenter/ESXi records to reconstruct the path from the edge to the hypervisor.
BianLian: Exfiltration-Based Extortion
A threat actor with a valid domain account and no MFA to stop them lands on an internet-facing RDP jump host, spends the morning living off the land, dumps credentials from LSASS, and spends the afternoon moving approximately 47 GB of engineering documents out of the network through a cloud-sync utility pointed at storage they control. No files are encrypted; the leverage is the stolen data itself. Reconstruct the full chain from initial RDP spray to log wipe.
Rhysida Ransomware: Healthcare Network Intrusion
A Rhysida ransomware affiliate phishes a healthcare staff member's VPN credentials and exploits a stale MFA exemption to breach a regional medical center. Using a Cobalt Strike beacon and built-in Windows tools, the attacker extracts all domain credentials, exfiltrates patient records for double extortion, and deploys the encryptor estate-wide. Trace the kill chain from the first failed VPN login to the final ransom note.