ZeroHour

play

ransomware group · aka Play, PlayCrypt, Water Curupira Pikapilya (Trend Micro tracking name) · unknown; widely assessed as likely Russia-based, though no confirmed attribution · active since 2022

Victims · 7d
2flat
Victims · 30d
11active targets
Victims · 90d
44
All-time (tracked)
1.3Ksince 2022-11-26
Last post
09-10 21:44UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Play (PlayCrypt) is a double-extortion ransomware group first publicly documented in 2022, known for a leak-first extortion model, distinctive ransom notes that omit ransom amounts and contact details, and encryption support for Windows, Linux, and FreeBSD. Victim sectors reported include government facilities, critical infrastructure, education facilities, information technology, healthcare/public health, financial services, and manufacturing, across North America, South America, and Europe. Per the FBI/CISA #StopRansomware advisory update (December 2024), Play had affected approximately 900 organizations worldwide, up from about 300 as of July 2023. The group gains access by exploiting known vulnerabilities in internet-facing appliances and remote-monitoring/management (RMM) software, supplemented by valid-account use. Dashboard tracking: 2 victims in the last 7/30/90 days, 2 total since 2026-09-09; last post 2026-09-09.

Tactics & tooling
  • Exploits known vulnerabilities in Fortinet devices for initial access (CVE-2018-13379, CVE-2020-12812, CVE-2020-15310) per FBI/CISA advisory (2024 update)
  • Exploited SimpleHelp RMM path-traversal flaw CVE-2024-5776 as an access vector per FBI/CISA advisory (January 2025)
  • Uses valid accounts, RDP, and RMM/remote-access tooling for lateral movement and persistence
  • Living-off-the-land operations: GPO and scheduled-task deployment, disabling Microsoft Defender, use of batch/PowerShell tooling (FBI/CISA, 2023)
  • Exfiltrates victim data before encryption; reported use of rsync for data transfer
  • Double extortion via Tor-based 'Play News' leak site; ransom notes characteristically lack ransom amount and initial contact information
  • Encrypts across Windows, Linux, and FreeBSD systems
Targeted sectors
GovernmentCritical infrastructureEducationInformation technologyHealthcare/public healthFinancial servicesManufacturing
Notable public victims

Dallas County, Texas (2023; attribution via widely reported press coverage), Red Star Oil (leak-site post tracked by this dashboard, posted 2026-09-09), GT Distributors (leak-site post tracked by this dashboard, posted 2026-09-09)

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
PermaCold Engineering · May 1, 2025
Missouri Pipe Fittings · May 1, 2025
Cooper Global Chauffeured · May 1, 2025
BOLL Logistik · May 1, 2025
Gorham Sand & Gravel · May 1, 2025
FMT Consultants · Apr 28, 2025
Mantel Machine Products · Apr 28, 2025
Scientel Solutions · Apr 28, 2025
Haas & Associates · Apr 28, 2025
Crawford Door Sales · Apr 28, 2025
Jet Ice · Apr 22, 2025
Independent Financial Services · Apr 22, 2025
NESCTC · Apr 22, 2025
The Human Bean · Apr 22, 2025
Lantronix · Apr 22, 2025
All Book Covers · Apr 22, 2025
Suburban Carting · Apr 22, 2025
Red Chamber · Apr 16, 2025
Waller · Apr 15, 2025
Miller Boskus Lack Architects · Apr 15, 2025
Cortez Resources · Apr 15, 2025
Comport Technology Solutions · Apr 15, 2025
Merri-Makers · Apr 15, 2025
O'Brien & Ryan · Apr 15, 2025
Voigt-Abernathy Company · Apr 15, 2025
Destination Toronto · Apr 15, 2025
James & Sons Fine Jewelers · Apr 15, 2025
Calmont Group · Apr 14, 2025
C?l???t Group · Apr 11, 2025
Bonick Landscaping · Apr 10, 2025
Sfrent.net · Apr 10, 2025
The Study · Apr 10, 2025
Codinter · Apr 10, 2025
PAC Strapping Products · Apr 10, 2025
New York Sports Club · Apr 10, 2025
Noyen Construction · Apr 10, 2025
KER Custom Molders · Apr 10, 2025
Cane Creek Cycling Components · Apr 10, 2025
ABITL Finishing · Apr 5, 2025
Baltimore Steel Erectors · Apr 5, 2025
Hawk Technology · Apr 5, 2025
Csm Engineering · Apr 5, 2025
Royal Glass · Apr 4, 2025
Fraser Trebilcock · Apr 4, 2025
Hop Industries · Apr 2, 2025
Lifebreath · Apr 2, 2025
Parvin-Clauss Sign Company · Apr 2, 2025
OTA Management · Apr 2, 2025
Fulfillment Plus · Apr 2, 2025
Regionale Verkehrsbetriebe · Apr 2, 2025

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .