ZeroHour

play

ransomware group · aka Play, PlayCrypt, Water Curupira Pikapilya (Trend Micro tracking name) · unknown; widely assessed as likely Russia-based, though no confirmed attribution · active since 2022

Victims · 7d
4▲4 vs prev. week
Victims · 30d
14active targets
Victims · 90d
44
All-time (tracked)
1.3Ksince 2022-11-26
Last post
09-10 21:44UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Play (PlayCrypt) is a double-extortion ransomware group first publicly documented in 2022, known for a leak-first extortion model, distinctive ransom notes that omit ransom amounts and contact details, and encryption support for Windows, Linux, and FreeBSD. Victim sectors reported include government facilities, critical infrastructure, education facilities, information technology, healthcare/public health, financial services, and manufacturing, across North America, South America, and Europe. Per the FBI/CISA #StopRansomware advisory update (December 2024), Play had affected approximately 900 organizations worldwide, up from about 300 as of July 2023. The group gains access by exploiting known vulnerabilities in internet-facing appliances and remote-monitoring/management (RMM) software, supplemented by valid-account use. Dashboard tracking: 2 victims in the last 7/30/90 days, 2 total since 2026-09-09; last post 2026-09-09.

Tactics & tooling
  • Exploits known vulnerabilities in Fortinet devices for initial access (CVE-2018-13379, CVE-2020-12812, CVE-2020-15310) per FBI/CISA advisory (2024 update)
  • Exploited SimpleHelp RMM path-traversal flaw CVE-2024-5776 as an access vector per FBI/CISA advisory (January 2025)
  • Uses valid accounts, RDP, and RMM/remote-access tooling for lateral movement and persistence
  • Living-off-the-land operations: GPO and scheduled-task deployment, disabling Microsoft Defender, use of batch/PowerShell tooling (FBI/CISA, 2023)
  • Exfiltrates victim data before encryption; reported use of rsync for data transfer
  • Double extortion via Tor-based 'Play News' leak site; ransom notes characteristically lack ransom amount and initial contact information
  • Encrypts across Windows, Linux, and FreeBSD systems
Targeted sectors
GovernmentCritical infrastructureEducationInformation technologyHealthcare/public healthFinancial servicesManufacturing
Notable public victims

Dallas County, Texas (2023; attribution via widely reported press coverage), Red Star Oil (leak-site post tracked by this dashboard, posted 2026-09-09), GT Distributors (leak-site post tracked by this dashboard, posted 2026-09-09)

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
Sys-kool · 4d ago
Grunthal Welding & Supplies · 4d ago
Red Star Oil · 6d ago
GT Distributors · 6d ago
MEQ · 15d ago
Figgins Family Wine Estates · 15d ago
KRC Machine Tool Solutions · 15d ago
Meteor Group · 15d ago
Be Media · 26d ago
Latoplast · 26d ago
Coltrane Systems · 28d ago
Bridgeport Capital Services · 28d ago
Sam Pack Auto Group · 28d ago
Woodhaven Association · 28d ago
MIE Solutions · Aug 9, 2026
Rilpa Enterprises · Aug 9, 2026
Marconi Industrial Services · Aug 9, 2026
Signature Services · Aug 6, 2026
GCATS Investments · Aug 6, 2026
Platinum Group · Aug 6, 2026
First Tek · Aug 5, 2026
Preferred Financial Group · Aug 5, 2026
The Butcher Brothers · Aug 2, 2026
Sigma Plastics Group · Aug 2, 2026
Cambridge Management · Aug 2, 2026
Record Go Alquiler · Jul 23, 2026
Restaurant Depot · Jul 23, 2026
The DeBruler · Jul 23, 2026
Tax MT · Jul 22, 2026
Kreysler & Associates · Jul 22, 2026
Boston Electric and Telephone · Jul 16, 2026
Wring Group · Jul 16, 2026
AG Scholtes · Jul 16, 2026
Andorra Life · Jul 16, 2026
Svensk Direktreklam · Jul 16, 2026
Preneed Funeral Programs · Jul 7, 2026
Kevin Bao Lenguyen · Jul 7, 2026
United Infrastructure · Jul 7, 2026
Locati Architects · Jul 4, 2026
Silvestri & Associates Insurance · Jul 4, 2026
Western Construction · Jun 30, 2026
J&J Gaming · Jun 27, 2026
Kuhnline · Jun 27, 2026
Benchmark Industrial Supply · Jun 26, 2026
Greg Crosslin · Jun 17, 2026
Integrated Technologies · Jun 17, 2026
eurOptimum · Jun 17, 2026
Mundt and Associates · Jun 10, 2026
Rainbow Distributors USA · Jun 10, 2026
Pearson Ford · Jun 6, 2026

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .