ZeroHour

play

ransomware group · aka Play, PlayCrypt, Water Curupira Pikapilya (Trend Micro tracking name) · unknown; widely assessed as likely Russia-based, though no confirmed attribution · active since 2022

Victims · 7d
0▼4
Victims · 30d
10active targets
Victims · 90d
44
All-time (tracked)
1.3Ksince 2022-11-26
Last post
09-10 21:44UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Play (PlayCrypt) is a double-extortion ransomware group first publicly documented in 2022, known for a leak-first extortion model, distinctive ransom notes that omit ransom amounts and contact details, and encryption support for Windows, Linux, and FreeBSD. Victim sectors reported include government facilities, critical infrastructure, education facilities, information technology, healthcare/public health, financial services, and manufacturing, across North America, South America, and Europe. Per the FBI/CISA #StopRansomware advisory update (December 2024), Play had affected approximately 900 organizations worldwide, up from about 300 as of July 2023. The group gains access by exploiting known vulnerabilities in internet-facing appliances and remote-monitoring/management (RMM) software, supplemented by valid-account use. Dashboard tracking: 2 victims in the last 7/30/90 days, 2 total since 2026-09-09; last post 2026-09-09.

Tactics & tooling
  • Exploits known vulnerabilities in Fortinet devices for initial access (CVE-2018-13379, CVE-2020-12812, CVE-2020-15310) per FBI/CISA advisory (2024 update)
  • Exploited SimpleHelp RMM path-traversal flaw CVE-2024-5776 as an access vector per FBI/CISA advisory (January 2025)
  • Uses valid accounts, RDP, and RMM/remote-access tooling for lateral movement and persistence
  • Living-off-the-land operations: GPO and scheduled-task deployment, disabling Microsoft Defender, use of batch/PowerShell tooling (FBI/CISA, 2023)
  • Exfiltrates victim data before encryption; reported use of rsync for data transfer
  • Double extortion via Tor-based 'Play News' leak site; ransom notes characteristically lack ransom amount and initial contact information
  • Encrypts across Windows, Linux, and FreeBSD systems
Targeted sectors
GovernmentCritical infrastructureEducationInformation technologyHealthcare/public healthFinancial servicesManufacturing
Notable public victims

Dallas County, Texas (2023; attribution via widely reported press coverage), Red Star Oil (leak-site post tracked by this dashboard, posted 2026-09-09), GT Distributors (leak-site post tracked by this dashboard, posted 2026-09-09)

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
Red River Title · Mar 2, 2024
Compact Mould · Mar 2, 2024
Winona Pattern & Mold · Mar 2, 2024
Marketon · Mar 2, 2024
Stack Infrastructure · Mar 2, 2024
Coastal Car · Mar 2, 2024
New Bedford Welding Supply · Mar 2, 2024
Influence Communication · Mar 1, 2024
Kool-air · Mar 1, 2024
FBi Construction · Mar 1, 2024
Gilmore & Associates · Feb 29, 2024
Welch's · Feb 24, 2024
W???h? · Feb 23, 2024
LD Davis · Feb 15, 2024
von Hagen · Feb 15, 2024
Norman, Fox · Feb 15, 2024
HR Ewell & Hy-tec · Feb 15, 2024
Mechanical Reps · Feb 15, 2024
Onclusive · Feb 15, 2024
MeerServices · Feb 15, 2024
DuBose Strapping · Feb 15, 2024
SilverLining · Feb 15, 2024
Greenwich Leisure · Feb 6, 2024
Ready Mixed Concrete · Feb 6, 2024
Northeastern Sheet Metal · Feb 6, 2024
Hannon Transport · Feb 6, 2024
McMillan Pazdan Smith · Feb 6, 2024
Mason Construction · Feb 6, 2024
Albert Bartlett · Feb 6, 2024
Perry-McCall Construction · Feb 6, 2024
Virgin Islands Lottery · Feb 6, 2024
Premier Facility Management · Feb 6, 2024
Douglas County Libraries · Feb 6, 2024
Leaders Staffing · Feb 6, 2024
Innovex Downhole Solutions · Feb 2, 2024
TPG Architecture · Jan 19, 2024
Televerde · Jan 6, 2024
Madison Capital & WPM & The Time Group · Jan 2, 2024
M?????n C?????? & W?? & The ???? G???? · Dec 31, 2023
Keyser Mason Ball · Dec 30, 2023
CVR Associates · Dec 28, 2023
Owen Quilty Professional · Dec 21, 2023
Jon Richard · Dec 21, 2023
Concept Data · Dec 21, 2023
Packaging Solutions · Dec 21, 2023
Richard Harris Personal Injury Law Firm · Dec 19, 2023
Schoepe Display · Dec 19, 2023
Waldner's · Dec 18, 2023
Succes Schoonmaak · Dec 18, 2023
DYWIDAG-Systems & American Transportation · Dec 18, 2023

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .