Threadlinqs IntelligenceStart free

Threat actorTracked since 2026-06

Play - G1040

As of 2026-08-23, Play - G1040 is a threat actor tracked by Threadlinqs Intelligence across 2 threats spanning ransomware, malware. ATT&CK coverage spans 34 techniques across 12 tactics in 2 of 2 tracked threats. Most-observed techniques: T1001 (Data Obfuscation), T1003 (OS Credential Dumping), T1021 (Remote Services).

Tracked threats
21 critical · 1 high
First seen
2026-06-30
Last seen
2026-08-23
ATT&CK techniques
34across 2 of 2 threats
Related CVEs
8Referenced by its activity
2 tracked threat(s) · Categories: RANSOMWARE, MALWARE

Activity timeline

Play - G1040 appears in 2 tracked threats between and ; the busiest month was 2026-06 with 1 report.

ATT&CK techniques observed

34 techniques observed across 2 of 2 tracked threats · Command and Control (8), Stealth (formerly Defense Evasion) (5), Discovery (4), Initial Access (4), Credential Access (3), Execution (3)
  • T1001 Data Obfuscation — Command and Controlobserved in 1 of 2 tracked threats
  • T1003 OS Credential Dumping — Credential Accessobserved in 1 of 2 tracked threats
  • T1021 Remote Services — Lateral Movementobserved in 1 of 2 tracked threats
  • T1053 Scheduled Task/Job — Persistenceobserved in 1 of 2 tracked threats
  • T1057 Process Discovery — Discoveryobserved in 1 of 2 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 1 of 2 tracked threats
  • T1071 Application Layer Protocol — Command and Controlobserved in 1 of 2 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 1 of 2 tracked threats
  • T1087 Account Discovery — Discoveryobserved in 1 of 2 tracked threats
  • T1090 Proxy — Command and Controlobserved in 1 of 2 tracked threats
  • T1095 Non-Application Layer Protocol — Command and Controlobserved in 1 of 2 tracked threats
  • T1105 Ingress Tool Transfer — Command and Controlobserved in 1 of 2 tracked threats
  • T1106 Native API — Executionobserved in 1 of 2 tracked threats
  • T1124 System Time Discovery — Discoveryobserved in 1 of 2 tracked threats
  • T1133 External Remote Services — Initial Accessobserved in 1 of 2 tracked threats

Tracked threats

Related CVEs

8 CVEs referenced by tracked Play - G1040 activity