ZeroHour

play

ransomware group · aka Play, PlayCrypt, Water Curupira Pikapilya (Trend Micro tracking name) · unknown; widely assessed as likely Russia-based, though no confirmed attribution · active since 2022

Victims · 7d
2flat
Victims · 30d
11active targets
Victims · 90d
44
All-time (tracked)
1.3Ksince 2022-11-26
Last post
09-10 21:44UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Play (PlayCrypt) is a double-extortion ransomware group first publicly documented in 2022, known for a leak-first extortion model, distinctive ransom notes that omit ransom amounts and contact details, and encryption support for Windows, Linux, and FreeBSD. Victim sectors reported include government facilities, critical infrastructure, education facilities, information technology, healthcare/public health, financial services, and manufacturing, across North America, South America, and Europe. Per the FBI/CISA #StopRansomware advisory update (December 2024), Play had affected approximately 900 organizations worldwide, up from about 300 as of July 2023. The group gains access by exploiting known vulnerabilities in internet-facing appliances and remote-monitoring/management (RMM) software, supplemented by valid-account use. Dashboard tracking: 2 victims in the last 7/30/90 days, 2 total since 2026-09-09; last post 2026-09-09.

Tactics & tooling
  • Exploits known vulnerabilities in Fortinet devices for initial access (CVE-2018-13379, CVE-2020-12812, CVE-2020-15310) per FBI/CISA advisory (2024 update)
  • Exploited SimpleHelp RMM path-traversal flaw CVE-2024-5776 as an access vector per FBI/CISA advisory (January 2025)
  • Uses valid accounts, RDP, and RMM/remote-access tooling for lateral movement and persistence
  • Living-off-the-land operations: GPO and scheduled-task deployment, disabling Microsoft Defender, use of batch/PowerShell tooling (FBI/CISA, 2023)
  • Exfiltrates victim data before encryption; reported use of rsync for data transfer
  • Double extortion via Tor-based 'Play News' leak site; ransom notes characteristically lack ransom amount and initial contact information
  • Encrypts across Windows, Linux, and FreeBSD systems
Targeted sectors
GovernmentCritical infrastructureEducationInformation technologyHealthcare/public healthFinancial servicesManufacturing
Notable public victims

Dallas County, Texas (2023; attribution via widely reported press coverage), Red Star Oil (leak-site post tracked by this dashboard, posted 2026-09-09), GT Distributors (leak-site post tracked by this dashboard, posted 2026-09-09)

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
Thompson Construction Supply · Sep 20, 2024
Plaisted Companies · Sep 18, 2024
Baskervill · Sep 16, 2024
Protective Industrial Products · Sep 16, 2024
Inktel · Sep 16, 2024
Rsp · Sep 16, 2024
Hariri Pontarini Architects · Sep 16, 2024
Multidata · Sep 16, 2024
True Family Enterprises · Sep 13, 2024
Dimensional Merchandising · Sep 13, 2024
Creative Playthings · Sep 13, 2024
Evans Distribution Systems · Sep 10, 2024
Weldco-Beales Manufacturing · Sep 10, 2024
PIGGLY WIGGLY ALABAMA DISTRIBUTING · Sep 10, 2024
Elgin Separation Solutions · Sep 10, 2024
Bel-Air Bay Club · Sep 10, 2024
Joe Swartz Electric · Sep 10, 2024
Virginia Dare Extract Co. · Sep 10, 2024
Southeast Cooler · Sep 10, 2024
Farmers' Rice Cooperative · Sep 4, 2024
Bakersfield · Sep 4, 2024
Crain Group · Sep 4, 2024
Seirus Innovation · Sep 4, 2024
Epi Breads · Aug 28, 2024
Software Engineering Associates · Aug 28, 2024
GDB International · Aug 28, 2024
ABC Parts International · Aug 28, 2024
Universal Pure · Aug 28, 2024
Omicron Granite & Tile · Aug 28, 2024
Clabots · Aug 28, 2024
Microchip Technology · Aug 26, 2024
Precom · Aug 26, 2024
The SMS Group · Aug 21, 2024
Grid Subject Matter Experts · Aug 21, 2024
Quilvest Capital Partners · Aug 21, 2024
Armour Coatings · Aug 21, 2024
RCG · Aug 21, 2024
Policy Administration Solutions · Aug 21, 2024
Mill Creek Lumber · Aug 15, 2024
Parker Development Company · Aug 13, 2024
Air International Thermal Systems · Aug 13, 2024
Adina Design · Aug 13, 2024
CinemaTech · Aug 13, 2024
Erie Meats · Aug 13, 2024
M??? ????k ?????? · Aug 13, 2024
TelPro · Aug 11, 2024
Credible Group · Aug 9, 2024
Nilorngruppen AB · Aug 9, 2024
Alternate Energy · Aug 6, 2024
True Blue Environmental · Aug 6, 2024

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .