ZeroHour

play

ransomware group · aka Play, PlayCrypt, Water Curupira Pikapilya (Trend Micro tracking name) · unknown; widely assessed as likely Russia-based, though no confirmed attribution · active since 2022

Victims · 7d
2flat
Victims · 30d
10active targets
Victims · 90d
44
All-time (tracked)
1.3Ksince 2022-11-26
Last post
09-10 21:44UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Play (PlayCrypt) is a double-extortion ransomware group first publicly documented in 2022, known for a leak-first extortion model, distinctive ransom notes that omit ransom amounts and contact details, and encryption support for Windows, Linux, and FreeBSD. Victim sectors reported include government facilities, critical infrastructure, education facilities, information technology, healthcare/public health, financial services, and manufacturing, across North America, South America, and Europe. Per the FBI/CISA #StopRansomware advisory update (December 2024), Play had affected approximately 900 organizations worldwide, up from about 300 as of July 2023. The group gains access by exploiting known vulnerabilities in internet-facing appliances and remote-monitoring/management (RMM) software, supplemented by valid-account use. Dashboard tracking: 2 victims in the last 7/30/90 days, 2 total since 2026-09-09; last post 2026-09-09.

Tactics & tooling
  • Exploits known vulnerabilities in Fortinet devices for initial access (CVE-2018-13379, CVE-2020-12812, CVE-2020-15310) per FBI/CISA advisory (2024 update)
  • Exploited SimpleHelp RMM path-traversal flaw CVE-2024-5776 as an access vector per FBI/CISA advisory (January 2025)
  • Uses valid accounts, RDP, and RMM/remote-access tooling for lateral movement and persistence
  • Living-off-the-land operations: GPO and scheduled-task deployment, disabling Microsoft Defender, use of batch/PowerShell tooling (FBI/CISA, 2023)
  • Exfiltrates victim data before encryption; reported use of rsync for data transfer
  • Double extortion via Tor-based 'Play News' leak site; ransom notes characteristically lack ransom amount and initial contact information
  • Encrypts across Windows, Linux, and FreeBSD systems
Targeted sectors
GovernmentCritical infrastructureEducationInformation technologyHealthcare/public healthFinancial servicesManufacturing
Notable public victims

Dallas County, Texas (2023; attribution via widely reported press coverage), Red Star Oil (leak-site post tracked by this dashboard, posted 2026-09-09), GT Distributors (leak-site post tracked by this dashboard, posted 2026-09-09)

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
Granit Design · Aug 6, 2024
KinetX · Aug 6, 2024
The Computer Merchant · Jul 25, 2024
Williams Construction · Jul 25, 2024
Gateway Extrusions · Jul 25, 2024
Gendron & Gendron · Jul 25, 2024
Golden Business Machines · Jul 25, 2024
Odyssey Fitness Center · Jul 25, 2024
OfficeOps · Jul 25, 2024
Congoleum · Jul 23, 2024
C???o???m · Jul 17, 2024
Hayden Power Group · Jul 17, 2024
MIPS Technologies · Jul 17, 2024
Hyperice · Jul 12, 2024
Texas Electric Cooperatives · Jul 11, 2024
The 21st Century Energy Group · Jul 11, 2024
T P C I · Jul 11, 2024
Elyria Foundry · Jul 5, 2024
Texas Recycling · Jul 4, 2024
INDA's · Jul 4, 2024
Innerspec Technologies · Jul 4, 2024
Prairie Athletic Club · Jul 4, 2024
Fareri Associates · Jul 4, 2024
TPI · Jun 23, 2024
Harvey Construction · Jun 23, 2024
Belle Tire · Jun 23, 2024
Hedrick Brothers Construction · Jun 23, 2024
World inquest · Jun 23, 2024
Bunger Steel · Jun 23, 2024
RRCA Accounts Management · Jun 23, 2024
ProMotion Holdings · Jun 23, 2024
Custom Concrete · Jun 23, 2024
Ladco · Jun 23, 2024
Seagulf Marine Industries · Jun 12, 2024
Western Mechanical · Jun 12, 2024
Trisun Land Services · Jun 12, 2024
Goodman Reichwald-Dodge · Jun 12, 2024
3GL Technology Solutions · Jun 12, 2024
Brainworks Software · Jun 12, 2024
Eagle Materials · Jun 12, 2024
Great Lakes International Trading · Jun 12, 2024
Smartweb · Jun 12, 2024
Peterbilt of Atlanta · Jun 12, 2024
Chroma Color · Jun 12, 2024
Shinnick & Ryan · Jun 12, 2024
Amarilla Gas · Jun 12, 2024
Aldenhoven · Jun 12, 2024
ANTECH-GUTLING Gruppe · Jun 12, 2024
Refcio & Associates · Jun 12, 2024
City Builders · Jun 12, 2024

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .