🇷🇺Play
🇷🇺 Play is a tracked threat actor in the Clankerusecase corpus. Attributed to RU. Primary motivation: Criminal. We map 26 detection use cases to this actor across 47 MITRE ATT&CK techniques, with 1 threat-intel article citing them. Active in our corpus from 2026-05-28 to 2026-05-28.
crit 1
26Use cases
1Articles
47Techniques
0IOCs
Known aliases
Play ransomwarePlayCryptBalloonflyPlay
Top techniques
All other tracked techniques
T1003 · OS Credential DumpingT1003.001 · LSASS MemoryT1016 · System Network Configuration DiscoveryT1018 · Remote System DiscoveryT1021.002 · SMB/Windows Admin SharesT1027.010 · Command ObfuscationT1030 · Data Transfer Size LimitsT1048 · Exfiltration Over Alternative ProtocolT1057 · Process DiscoveryT1059.001 · PowerShellT1059.003 · Windows Command ShellT1059.005 · Visual BasicT1070.004 · File DeletionT1071.001 · Web ProtocolsT1071.004 · DNST1078 · Valid AccountsT1078.002 · Domain AccountsT1078.003 · Local AccountsT1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1105 · Ingress Tool TransferT1133 · External Remote ServicesT1204.001 · Malicious LinkT1204.002 · Malicious FileT1218 · System Binary Proxy ExecutionT1486 · Data Encrypted for ImpactT1498 · Network Denial of ServiceT1518.001 · Security Software DiscoveryT1539 · Steal Web Session CookieT1555.003 · Credentials from Web BrowsersT1560.001 · Archive via UtilityT1566 · PhishingT1566.001 · Spearphishing AttachmentT1566.002 · Spearphishing LinkT1566.004 · Spearphishing VoiceT1569.002 · Service ExecutionT1583.001 · DomainsT1583.003 · Virtual Private ServerT1587.001 · MalwareT1588.002 · ToolT1598.003 · Spearphishing LinkT1657 · Financial TheftT1685 · Disable or Modify ToolsT1685.005 · Clear Windows Event Logs