ZeroHour

play

ransomware group · aka Play, PlayCrypt, Water Curupira Pikapilya (Trend Micro tracking name) · unknown; widely assessed as likely Russia-based, though no confirmed attribution · active since 2022

Victims · 7d
0▼4
Victims · 30d
10active targets
Victims · 90d
44
All-time (tracked)
1.3Ksince 2022-11-26
Last post
09-10 21:44UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Play (PlayCrypt) is a double-extortion ransomware group first publicly documented in 2022, known for a leak-first extortion model, distinctive ransom notes that omit ransom amounts and contact details, and encryption support for Windows, Linux, and FreeBSD. Victim sectors reported include government facilities, critical infrastructure, education facilities, information technology, healthcare/public health, financial services, and manufacturing, across North America, South America, and Europe. Per the FBI/CISA #StopRansomware advisory update (December 2024), Play had affected approximately 900 organizations worldwide, up from about 300 as of July 2023. The group gains access by exploiting known vulnerabilities in internet-facing appliances and remote-monitoring/management (RMM) software, supplemented by valid-account use. Dashboard tracking: 2 victims in the last 7/30/90 days, 2 total since 2026-09-09; last post 2026-09-09.

Tactics & tooling
  • Exploits known vulnerabilities in Fortinet devices for initial access (CVE-2018-13379, CVE-2020-12812, CVE-2020-15310) per FBI/CISA advisory (2024 update)
  • Exploited SimpleHelp RMM path-traversal flaw CVE-2024-5776 as an access vector per FBI/CISA advisory (January 2025)
  • Uses valid accounts, RDP, and RMM/remote-access tooling for lateral movement and persistence
  • Living-off-the-land operations: GPO and scheduled-task deployment, disabling Microsoft Defender, use of batch/PowerShell tooling (FBI/CISA, 2023)
  • Exfiltrates victim data before encryption; reported use of rsync for data transfer
  • Double extortion via Tor-based 'Play News' leak site; ransom notes characteristically lack ransom amount and initial contact information
  • Encrypts across Windows, Linux, and FreeBSD systems
Targeted sectors
GovernmentCritical infrastructureEducationInformation technologyHealthcare/public healthFinancial servicesManufacturing
Notable public victims

Dallas County, Texas (2023; attribution via widely reported press coverage), Red Star Oil (leak-site post tracked by this dashboard, posted 2026-09-09), GT Distributors (leak-site post tracked by this dashboard, posted 2026-09-09)

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
Inclinator · Nov 9, 2023
Crown Supply Co · Nov 9, 2023
GeoPoint Surveying · Nov 3, 2023
Bry-Air · Nov 2, 2023
JDRM Engineering · Nov 2, 2023
Craft-Maid · Nov 2, 2023
Hilyard's · Nov 2, 2023
North Dakota Grain Inspection Services · Nov 2, 2023
Gsp Components · Nov 2, 2023
Ricardo · Nov 2, 2023
G??P???? S????y??? · Oct 31, 2023
Brodart · Oct 30, 2023
Dallas County · Oct 28, 2023
Alpha Mortgage · Oct 28, 2023
Encompass Elements · Oct 28, 2023
CK Associates · Oct 28, 2023
Yingling Aviation · Oct 28, 2023
Sam Tell Companies · Oct 28, 2023
Waterstone Faucets · Oct 28, 2023
Bush Refrigeration · Oct 28, 2023
Drug Emporium · Oct 28, 2023
Online Development · Oct 28, 2023
KDI Office Technology · Oct 28, 2023
Het Veer · Oct 28, 2023
Laiho Group · Oct 27, 2023
Williamson Foodservice · Oct 20, 2023
Epaccsys · Oct 20, 2023
Tru-val Electric · Oct 20, 2023
Bridgeport Fittings · Oct 20, 2023
Kobi Karp Architecture and Interior Design · Oct 20, 2023
RADISE · Oct 20, 2023
Polar Tech Industries · Oct 20, 2023
Ipswich Bay Glass · Oct 20, 2023
Hygieneering · Oct 20, 2023
The Fountain Group · Oct 20, 2023
Venture Plastics · Oct 20, 2023
Milk Source · Oct 20, 2023
Associated Wholesale Grocers · Oct 19, 2023
Metro Transit · Oct 11, 2023
Starr Finley · Oct 10, 2023
WCM Europe · Oct 10, 2023
NachtExpress Austria GmbH · Oct 10, 2023
Centek industries · Oct 10, 2023
M??? T?????? · Oct 10, 2023
Saltire Energy · Oct 10, 2023
Hughes Gill Cochrane Tinetti · Oct 10, 2023
Roof Management · Oct 4, 2023
Security Instrument · Oct 4, 2023
Filtration Control · Oct 4, 2023
Cinepolis USA · Oct 4, 2023

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .