Play

APT / StateG1040 ↗
Techniques (MITRE ATT&CK)26
SourceMITRE ATT&CK

Vexday analysis

Play é um grupo de ransomware ativo desde pelo menos 2022, responsável pela implantação do ransomware Playcrypt contra organizações dos setores empresarial, governamental, de infraestrutura crítica, saúde e mídia na América do Norte, América do Sul e Europa. O grupo adota o modelo de dupla extorsão, exfiltrando dados antes de criptografar os sistemas das vítimas, e é classificado por pesquisadores de segurança como uma operação fechada. Catalogado no MITRE ATT&CK sob o identificador G1040, o Play possui 26 técnicas documentadas e 6 CVEs atribuídas à sua atuação.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity73
Impact: High
T1190T1059.001T1133T1003.001T1560.001T1030ENTRYInitial accessExploitPublic-Facing App…EXECExecutionPowerShellPERSPersistenceExternal RemoteServicesCREDCredential accessLSASS MemoryCOLLCollectionArchive viaUtilityEXFILExfiltrationData Transfer SizeLimitsIMPACTImpactFinancial Theft

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Exploited vulnerabilities 6

CVEs this group is known to exploit, per MITRE ATT&CK. Ordered by real-world severity.

Impact and victims

The group Play has 1 known ransomware victims. See the most affected sectors and countries and recent victims.

1known victims
1in Brazil
1sectors hit
Most attacked sectors
Manufacturing1
Most affected countries
🇧🇷 Brasil1
Recent victims
MetallcoManufacturing · BR · 2026-09-21

Known infrastructure 2887

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

ip:port104.143.204.78:8443Cobalt Strikethreatfox
ip:port156.239.4.189:50050Cobalt Strikethreatfox
md5_hashaaed196675895fcb5816edf09b0cb120Cobalt Strikethreatfox
ip:port153.80.242.105:8080Cobalt Strikethreatfox
ip:port153.80.242.105:443Cobalt Strikethreatfox
ip:port153.80.242.105:80Cobalt Strikethreatfox
ip:port47.114.83.19:8084Cobalt Strikethreatfox
ip:port153.80.242.105:9999Cobalt Strikethreatfox
ip:port95.217.135.208:8443Cobalt Strikethreatfox
ip:port46.19.140.50:8080Cobalt Strikethreatfox
ip:port46.19.140.50:443Cobalt Strikethreatfox
ip:port46.19.140.50:80Cobalt Strikethreatfox
ip:port46.19.140.50:22Cobalt Strikethreatfox
ip:port104.143.204.78:8080Cobalt Strikethreatfox
ip:port104.143.204.78:443Cobalt Strikethreatfox
ip:port104.143.204.78:80Cobalt Strikethreatfox
ip:port104.143.204.78:22Cobalt Strikethreatfox
ip:port114.215.184.158:1099Cobalt Strikethreatfox
ip:port95.217.135.208:8080Cobalt Strikethreatfox
ip:port114.215.184.158:22Cobalt Strikethreatfox
ip:port95.217.135.208:80Cobalt Strikethreatfox
ip:port95.217.135.208:443Cobalt Strikethreatfox
ip:port95.217.135.208:22Cobalt Strikethreatfox
ip:port156.239.4.189:8889Cobalt Strikethreatfox
ip:port114.66.27.110:8434Cobalt Strikethreatfox
ip:port101.35.217.145:50050Cobalt Strikethreatfox
ip:port121.127.33.186:8080Cobalt Strikethreatfox
ip:port121.127.33.186:80Cobalt Strikethreatfox
ip:port121.127.33.186:443Cobalt Strikethreatfox
ip:port121.127.33.186:22Cobalt Strikethreatfox

+2887 indicators in total. See them all on the IOCs page.

Play uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →