ZeroHour

play

ransomware group · aka Play, PlayCrypt, Water Curupira Pikapilya (Trend Micro tracking name) · unknown; widely assessed as likely Russia-based, though no confirmed attribution · active since 2022

Victims · 7d
2flat
Victims · 30d
11active targets
Victims · 90d
44
All-time (tracked)
1.3Ksince 2022-11-26
Last post
09-10 21:44UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Play (PlayCrypt) is a double-extortion ransomware group first publicly documented in 2022, known for a leak-first extortion model, distinctive ransom notes that omit ransom amounts and contact details, and encryption support for Windows, Linux, and FreeBSD. Victim sectors reported include government facilities, critical infrastructure, education facilities, information technology, healthcare/public health, financial services, and manufacturing, across North America, South America, and Europe. Per the FBI/CISA #StopRansomware advisory update (December 2024), Play had affected approximately 900 organizations worldwide, up from about 300 as of July 2023. The group gains access by exploiting known vulnerabilities in internet-facing appliances and remote-monitoring/management (RMM) software, supplemented by valid-account use. Dashboard tracking: 2 victims in the last 7/30/90 days, 2 total since 2026-09-09; last post 2026-09-09.

Tactics & tooling
  • Exploits known vulnerabilities in Fortinet devices for initial access (CVE-2018-13379, CVE-2020-12812, CVE-2020-15310) per FBI/CISA advisory (2024 update)
  • Exploited SimpleHelp RMM path-traversal flaw CVE-2024-5776 as an access vector per FBI/CISA advisory (January 2025)
  • Uses valid accounts, RDP, and RMM/remote-access tooling for lateral movement and persistence
  • Living-off-the-land operations: GPO and scheduled-task deployment, disabling Microsoft Defender, use of batch/PowerShell tooling (FBI/CISA, 2023)
  • Exfiltrates victim data before encryption; reported use of rsync for data transfer
  • Double extortion via Tor-based 'Play News' leak site; ransom notes characteristically lack ransom amount and initial contact information
  • Encrypts across Windows, Linux, and FreeBSD systems
Targeted sectors
GovernmentCritical infrastructureEducationInformation technologyHealthcare/public healthFinancial servicesManufacturing
Notable public victims

Dallas County, Texas (2023; attribution via widely reported press coverage), Red Star Oil (leak-site post tracked by this dashboard, posted 2026-09-09), GT Distributors (leak-site post tracked by this dashboard, posted 2026-09-09)

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
Artemis Holding · Dec 12, 2024
Arnott · Dec 12, 2024
Standard Calibrations · Dec 5, 2024
NatAlliance Securities · Dec 5, 2024
ITO EN · Dec 5, 2024
Max Trans · Dec 5, 2024
Trace3 · Nov 29, 2024
Bendheim · Nov 29, 2024
Specialty Bolt And Screw · Nov 29, 2024
LenelS2 · Nov 21, 2024
Henderson Stamping & Production · Nov 19, 2024
Diamond Brand Gear · Nov 19, 2024
Dairy Farmers of Canada · Nov 19, 2024
Miller & Smith · Nov 19, 2024
Hive Power Engineering · Nov 19, 2024
CMD · Nov 19, 2024
IVC Technologies · Nov 19, 2024
Birdair · Nov 19, 2024
Vox Printing · Nov 19, 2024
Postcard Mania · Nov 7, 2024
Paragon Plastics · Nov 6, 2024
Delfin Design & Manufacturing · Nov 6, 2024
Smitty's Supply · Nov 6, 2024
S & W Kitchens · Nov 6, 2024
Dome Construction · Nov 6, 2024
JS McCarthy Printers · Nov 1, 2024
CGR Technologies · Nov 1, 2024
Maval Industries · Oct 30, 2024
Unlimited Lawn Care · Oct 30, 2024
Pureflow Airdog · Oct 30, 2024
iFocus Consulting · Oct 30, 2024
Pelsue · Oct 30, 2024
Paul White Company · Oct 30, 2024
Sunrise Express · Oct 30, 2024
Astac · Oct 30, 2024
Dana Safety Supply · Oct 29, 2024
Dirksen Screw Products · Oct 29, 2024
TV Guide Magazine · Oct 26, 2024
Positive Business Solutions · Oct 26, 2024
C & C Industries · Oct 26, 2024
Iron World Manufacturing · Oct 24, 2024
Eagle Industries · Oct 24, 2024
Action Heating & Cooling · Oct 24, 2024
Mainelli Mechanical Contractors · Oct 24, 2024
TU Parks · Oct 24, 2024
Ivanhoe Club · Oct 23, 2024
The Strainrite Companies · Oct 18, 2024
Wilkinson · Oct 18, 2024
Mid State Electric · Oct 18, 2024
Absolute Machine Tools · Oct 18, 2024

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .