ZeroHour

play

ransomware group · aka Play, PlayCrypt, Water Curupira Pikapilya (Trend Micro tracking name) · unknown; widely assessed as likely Russia-based, though no confirmed attribution · active since 2022

Victims · 7d
2flat
Victims · 30d
11active targets
Victims · 90d
44
All-time (tracked)
1.3Ksince 2022-11-26
Last post
09-10 21:44UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Play (PlayCrypt) is a double-extortion ransomware group first publicly documented in 2022, known for a leak-first extortion model, distinctive ransom notes that omit ransom amounts and contact details, and encryption support for Windows, Linux, and FreeBSD. Victim sectors reported include government facilities, critical infrastructure, education facilities, information technology, healthcare/public health, financial services, and manufacturing, across North America, South America, and Europe. Per the FBI/CISA #StopRansomware advisory update (December 2024), Play had affected approximately 900 organizations worldwide, up from about 300 as of July 2023. The group gains access by exploiting known vulnerabilities in internet-facing appliances and remote-monitoring/management (RMM) software, supplemented by valid-account use. Dashboard tracking: 2 victims in the last 7/30/90 days, 2 total since 2026-09-09; last post 2026-09-09.

Tactics & tooling
  • Exploits known vulnerabilities in Fortinet devices for initial access (CVE-2018-13379, CVE-2020-12812, CVE-2020-15310) per FBI/CISA advisory (2024 update)
  • Exploited SimpleHelp RMM path-traversal flaw CVE-2024-5776 as an access vector per FBI/CISA advisory (January 2025)
  • Uses valid accounts, RDP, and RMM/remote-access tooling for lateral movement and persistence
  • Living-off-the-land operations: GPO and scheduled-task deployment, disabling Microsoft Defender, use of batch/PowerShell tooling (FBI/CISA, 2023)
  • Exfiltrates victim data before encryption; reported use of rsync for data transfer
  • Double extortion via Tor-based 'Play News' leak site; ransom notes characteristically lack ransom amount and initial contact information
  • Encrypts across Windows, Linux, and FreeBSD systems
Targeted sectors
GovernmentCritical infrastructureEducationInformation technologyHealthcare/public healthFinancial servicesManufacturing
Notable public victims

Dallas County, Texas (2023; attribution via widely reported press coverage), Red Star Oil (leak-site post tracked by this dashboard, posted 2026-09-09), GT Distributors (leak-site post tracked by this dashboard, posted 2026-09-09)

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
usCalibration · Mar 25, 2025
B&C Industries · Mar 25, 2025
Kimco Steel · Mar 25, 2025
REOC San Antonio · Mar 22, 2025
Zaveta Custom Homes · Mar 22, 2025
Q railing · Mar 19, 2025
SL Tennessee Information · Mar 13, 2025
Backes · Mar 13, 2025
Best Cheer Stone · Mar 13, 2025
Jerue Companies · Mar 9, 2025
Syma-System · Mar 9, 2025
Compound Solutions · Mar 9, 2025
T J Machine & Tool · Mar 9, 2025
Gevril · Mar 9, 2025
Peak Season · Mar 9, 2025
Yorke & Curtis · Mar 9, 2025
Buckley BalaWilson Mew · Mar 9, 2025
Holiday Comfort · Mar 9, 2025
Clawson Honda · Mar 9, 2025
Dectron · Mar 9, 2025
Nor Arc · Mar 9, 2025
Pre Con Industries · Mar 2, 2025
IT-IQ Botswana · Mar 2, 2025
North American Fire Hose · Mar 2, 2025
Couri Insurance Agency · Mar 2, 2025
M&n Management · Mar 2, 2025
Optometrics · Mar 2, 2025
International Process Plants · Mar 2, 2025
Ganong Bros · Mar 2, 2025
3cBSI · Feb 26, 2025
Finck Cigar · Feb 26, 2025
Story Environmental · Feb 26, 2025
Muller Insurance · Feb 26, 2025
Convert Solar · Feb 25, 2025
Radco Industries · Feb 25, 2025
Fairhaven Shipyard Companies · Feb 25, 2025
Island Realty · Feb 25, 2025
First Federal Savings & Loan · Feb 25, 2025
ALCOTT HR GROUP · Feb 25, 2025
Cuna Supply · Feb 17, 2025
The Townsley Law Firm Information · Feb 17, 2025
Bushmans · Feb 17, 2025
Inland Empire Distribution Systems, Inc. · Feb 17, 2025
Wylie Steel Fabricators · Feb 17, 2025
Oxford Companies · Feb 17, 2025
Stage 3 Separation · Feb 17, 2025
Transkid · Feb 17, 2025
Rheinischer Sch · Feb 17, 2025
Startek Peglar & Calcagni · Feb 17, 2025
Weed Man Canada · Feb 17, 2025

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .