ZeroHour

play

ransomware group · aka Play, PlayCrypt, Water Curupira Pikapilya (Trend Micro tracking name) · unknown; widely assessed as likely Russia-based, though no confirmed attribution · active since 2022

Victims · 7d
2flat
Victims · 30d
11active targets
Victims · 90d
44
All-time (tracked)
1.3Ksince 2022-11-26
Last post
09-10 21:44UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Play (PlayCrypt) is a double-extortion ransomware group first publicly documented in 2022, known for a leak-first extortion model, distinctive ransom notes that omit ransom amounts and contact details, and encryption support for Windows, Linux, and FreeBSD. Victim sectors reported include government facilities, critical infrastructure, education facilities, information technology, healthcare/public health, financial services, and manufacturing, across North America, South America, and Europe. Per the FBI/CISA #StopRansomware advisory update (December 2024), Play had affected approximately 900 organizations worldwide, up from about 300 as of July 2023. The group gains access by exploiting known vulnerabilities in internet-facing appliances and remote-monitoring/management (RMM) software, supplemented by valid-account use. Dashboard tracking: 2 victims in the last 7/30/90 days, 2 total since 2026-09-09; last post 2026-09-09.

Tactics & tooling
  • Exploits known vulnerabilities in Fortinet devices for initial access (CVE-2018-13379, CVE-2020-12812, CVE-2020-15310) per FBI/CISA advisory (2024 update)
  • Exploited SimpleHelp RMM path-traversal flaw CVE-2024-5776 as an access vector per FBI/CISA advisory (January 2025)
  • Uses valid accounts, RDP, and RMM/remote-access tooling for lateral movement and persistence
  • Living-off-the-land operations: GPO and scheduled-task deployment, disabling Microsoft Defender, use of batch/PowerShell tooling (FBI/CISA, 2023)
  • Exfiltrates victim data before encryption; reported use of rsync for data transfer
  • Double extortion via Tor-based 'Play News' leak site; ransom notes characteristically lack ransom amount and initial contact information
  • Encrypts across Windows, Linux, and FreeBSD systems
Targeted sectors
GovernmentCritical infrastructureEducationInformation technologyHealthcare/public healthFinancial servicesManufacturing
Notable public victims

Dallas County, Texas (2023; attribution via widely reported press coverage), Red Star Oil (leak-site post tracked by this dashboard, posted 2026-09-09), GT Distributors (leak-site post tracked by this dashboard, posted 2026-09-09)

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
Bulldog Oilfield Services · Feb 17, 2025
Shields Facilities Maintenance · Feb 13, 2025
Tie Down Engineering · Feb 12, 2025
Monroe Transportation Services Inc · Feb 12, 2025
Kensington Glass Arts · Feb 12, 2025
EAC Consulting · Feb 12, 2025
Baltimore Country Club · Feb 12, 2025
Jildor Shoes · Feb 12, 2025
Mainline Information Systems · Feb 12, 2025
Fastighetsservice AB · Feb 12, 2025
Shinn Fu Company of America · Feb 12, 2025
ROCK SOLID Stabilization & Reclamation · Feb 12, 2025
Cold Storage Manufacturing · Feb 12, 2025
Neaton Auto Products Manufacturing · Feb 12, 2025
Mid-State Machine & Fabricating Corp · Feb 5, 2025
Dickerson & Nieman Realtors · Feb 3, 2025
Sheridan Nurseries · Feb 3, 2025
The Hill Brush · Feb 3, 2025
DPC Development · Feb 3, 2025
Woodway USA · Feb 3, 2025
Daniel Island Club · Feb 3, 2025
KWS · Feb 3, 2025
QGS Development · Feb 3, 2025
Night Hawk · Jan 31, 2025
By design · Jan 29, 2025
Cahoon Farms · Jan 29, 2025
Marshall & Bruce Printing · Jan 29, 2025
Johnston · Jan 29, 2025
Plymouth Foam · Jan 29, 2025
Commercial & Residential Management Group · Jan 29, 2025
daVinci · Jan 29, 2025
TRIVAD · Jan 29, 2025
Wallin & Klarich · Jan 29, 2025
Cimarron Telephone Company · Jan 29, 2025
McCray Lumber · Dec 30, 2024
Zeifmans · Dec 30, 2024
Luxury Yacht Group · Dec 30, 2024
Bettisworth North · Dec 30, 2024
Krispy Kreme · Dec 19, 2024
Joshua Grading & Excavating · Dec 16, 2024
South Plains Implement · Dec 16, 2024
Chemitex SA Information · Dec 16, 2024
Hatfield Consultants · Dec 16, 2024
Lanigan Ryan · Dec 16, 2024
Welker · Dec 16, 2024
Sigarth · Dec 13, 2024
Long Beach Convention Center · Dec 13, 2024
Maxus Group · Dec 13, 2024
SBW · Dec 12, 2024
Sunline · Dec 12, 2024

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .