ZeroHour

play

ransomware group · aka Play, PlayCrypt, Water Curupira Pikapilya (Trend Micro tracking name) · unknown; widely assessed as likely Russia-based, though no confirmed attribution · active since 2022

Victims · 7d
2flat
Victims · 30d
10active targets
Victims · 90d
44
All-time (tracked)
1.3Ksince 2022-11-26
Last post
09-10 21:44UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Play (PlayCrypt) is a double-extortion ransomware group first publicly documented in 2022, known for a leak-first extortion model, distinctive ransom notes that omit ransom amounts and contact details, and encryption support for Windows, Linux, and FreeBSD. Victim sectors reported include government facilities, critical infrastructure, education facilities, information technology, healthcare/public health, financial services, and manufacturing, across North America, South America, and Europe. Per the FBI/CISA #StopRansomware advisory update (December 2024), Play had affected approximately 900 organizations worldwide, up from about 300 as of July 2023. The group gains access by exploiting known vulnerabilities in internet-facing appliances and remote-monitoring/management (RMM) software, supplemented by valid-account use. Dashboard tracking: 2 victims in the last 7/30/90 days, 2 total since 2026-09-09; last post 2026-09-09.

Tactics & tooling
  • Exploits known vulnerabilities in Fortinet devices for initial access (CVE-2018-13379, CVE-2020-12812, CVE-2020-15310) per FBI/CISA advisory (2024 update)
  • Exploited SimpleHelp RMM path-traversal flaw CVE-2024-5776 as an access vector per FBI/CISA advisory (January 2025)
  • Uses valid accounts, RDP, and RMM/remote-access tooling for lateral movement and persistence
  • Living-off-the-land operations: GPO and scheduled-task deployment, disabling Microsoft Defender, use of batch/PowerShell tooling (FBI/CISA, 2023)
  • Exfiltrates victim data before encryption; reported use of rsync for data transfer
  • Double extortion via Tor-based 'Play News' leak site; ransom notes characteristically lack ransom amount and initial contact information
  • Encrypts across Windows, Linux, and FreeBSD systems
Targeted sectors
GovernmentCritical infrastructureEducationInformation technologyHealthcare/public healthFinancial servicesManufacturing
Notable public victims

Dallas County, Texas (2023; attribution via widely reported press coverage), Red Star Oil (leak-site post tracked by this dashboard, posted 2026-09-09), GT Distributors (leak-site post tracked by this dashboard, posted 2026-09-09)

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
Engineered Automation of Maine · Apr 19, 2024
JE Owens · Apr 19, 2024
P??????? & ???? · Apr 19, 2024
Heritage Cooperative · Apr 16, 2024
Feldstein & Stewart · Apr 12, 2024
Agate Construction · Apr 12, 2024
H??????? C?????????? · Apr 12, 2024
MoldTech · Apr 11, 2024
Theatrixx Technologies · Apr 11, 2024
Access Intelligence · Apr 11, 2024
New England Wooden Ware · Apr 11, 2024
LS Networks · Apr 11, 2024
The MBTW Group · Apr 11, 2024
F???s???? & ??????t · Apr 10, 2024
Sit · Apr 4, 2024
Guy's Floor Service · Apr 4, 2024
Everbrite · Apr 4, 2024
Boingo Graphics · Apr 2, 2024
W?????? ????????y · Mar 29, 2024
Pavilion Construction · Mar 27, 2024
Tbr Kowalczyk · Mar 27, 2024
JM Thompson · Mar 27, 2024
Weld Plus · Mar 27, 2024
Festspielhaus Baden-Baden · Mar 27, 2024
West Monroe · Mar 27, 2024
Frawner · Mar 27, 2024
Alber Law Group · Mar 27, 2024
Hartz · Mar 27, 2024
Quality Enclosures · Mar 27, 2024
Lawrence Semiconductor Research Laboratory · Mar 27, 2024
Lambda Energy Resources · Mar 27, 2024
Schokinag · Mar 18, 2024
Bechtold · Mar 13, 2024
Canada Revenue Agency · Mar 11, 2024
White Oak Partners · Mar 11, 2024
Ruda Auto · Mar 11, 2024
Image Pointe · Mar 11, 2024
Grassmid Transport · Mar 11, 2024
Fashion UK · Mar 11, 2024
QI Group · Mar 11, 2024
BiTec · Mar 11, 2024
Bridger Insurance · Mar 11, 2024
SREE Hotels · Mar 11, 2024
Q?? ??o?? · Mar 11, 2024
Premier Technology · Mar 11, 2024
Continental Aerospace Technologies · Mar 9, 2024
MainVest · Mar 6, 2024
C?????????? A???????e T??????????? · Mar 6, 2024
K???o??? · Mar 6, 2024
Hedlunds · Mar 2, 2024

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .