Activity timeline
Play - G1040 appears in 2 tracked threats between and ; the busiest month was 2026-06 with 1 report.
ATT&CK techniques observed
- T1001 Data Obfuscation — Command and Controlobserved in 1 of 2 tracked threats
- T1003 OS Credential Dumping — Credential Accessobserved in 1 of 2 tracked threats
- T1021 Remote Services — Lateral Movementobserved in 1 of 2 tracked threats
- T1053 Scheduled Task/Job — Persistenceobserved in 1 of 2 tracked threats
- T1057 Process Discovery — Discoveryobserved in 1 of 2 tracked threats
- T1059 Command and Scripting Interpreter — Executionobserved in 1 of 2 tracked threats
- T1071 Application Layer Protocol — Command and Controlobserved in 1 of 2 tracked threats
- T1082 System Information Discovery — Discoveryobserved in 1 of 2 tracked threats
- T1087 Account Discovery — Discoveryobserved in 1 of 2 tracked threats
- T1090 Proxy — Command and Controlobserved in 1 of 2 tracked threats
- T1095 Non-Application Layer Protocol — Command and Controlobserved in 1 of 2 tracked threats
- T1105 Ingress Tool Transfer — Command and Controlobserved in 1 of 2 tracked threats
- T1106 Native API — Executionobserved in 1 of 2 tracked threats
- T1124 System Time Discovery — Discoveryobserved in 1 of 2 tracked threats
- T1133 External Remote Services — Initial Accessobserved in 1 of 2 tracked threats
Tracked threats
- 2026 Ransomware Surge Targeting US Organizations: Identity-First Compromise, BYOVD, and Living-Off-the-Cloud Exfiltration (Qilin, Akira, Clop, INC Ransom, Play, DragonForce, Sinobi)HIGH
- SystemBC (Coroxy) Malware: Tor-Based SOCKS5 Proxy Backdoor Enabling Ransomware Persistence and C2 ObfuscationCRITICAL