ZeroHour

play

ransomware group · aka Play, PlayCrypt, Water Curupira Pikapilya (Trend Micro tracking name) · unknown; widely assessed as likely Russia-based, though no confirmed attribution · active since 2022

Victims · 7d
0▼4
Victims · 30d
10active targets
Victims · 90d
44
All-time (tracked)
1.3Ksince 2022-11-26
Last post
09-10 21:44UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Play (PlayCrypt) is a double-extortion ransomware group first publicly documented in 2022, known for a leak-first extortion model, distinctive ransom notes that omit ransom amounts and contact details, and encryption support for Windows, Linux, and FreeBSD. Victim sectors reported include government facilities, critical infrastructure, education facilities, information technology, healthcare/public health, financial services, and manufacturing, across North America, South America, and Europe. Per the FBI/CISA #StopRansomware advisory update (December 2024), Play had affected approximately 900 organizations worldwide, up from about 300 as of July 2023. The group gains access by exploiting known vulnerabilities in internet-facing appliances and remote-monitoring/management (RMM) software, supplemented by valid-account use. Dashboard tracking: 2 victims in the last 7/30/90 days, 2 total since 2026-09-09; last post 2026-09-09.

Tactics & tooling
  • Exploits known vulnerabilities in Fortinet devices for initial access (CVE-2018-13379, CVE-2020-12812, CVE-2020-15310) per FBI/CISA advisory (2024 update)
  • Exploited SimpleHelp RMM path-traversal flaw CVE-2024-5776 as an access vector per FBI/CISA advisory (January 2025)
  • Uses valid accounts, RDP, and RMM/remote-access tooling for lateral movement and persistence
  • Living-off-the-land operations: GPO and scheduled-task deployment, disabling Microsoft Defender, use of batch/PowerShell tooling (FBI/CISA, 2023)
  • Exfiltrates victim data before encryption; reported use of rsync for data transfer
  • Double extortion via Tor-based 'Play News' leak site; ransom notes characteristically lack ransom amount and initial contact information
  • Encrypts across Windows, Linux, and FreeBSD systems
Targeted sectors
GovernmentCritical infrastructureEducationInformation technologyHealthcare/public healthFinancial servicesManufacturing
Notable public victims

Dallas County, Texas (2023; attribution via widely reported press coverage), Red Star Oil (leak-site post tracked by this dashboard, posted 2026-09-09), GT Distributors (leak-site post tracked by this dashboard, posted 2026-09-09)

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
CHARMANT Group · Oct 4, 2023
Stavanger Municipality · Oct 4, 2023
Jacobson · Sep 29, 2023
Robuck Homes · Sep 29, 2023
Webb Landscape · Sep 29, 2023
Amanzi Marble & Granite · Sep 29, 2023
BAMO · Sep 29, 2023
Van Eck Transport · Sep 29, 2023
Terralogic · Sep 29, 2023
Kessler Collins · Sep 29, 2023
Plumbase · Sep 29, 2023
Wexas · Sep 29, 2023
First Line · Sep 18, 2023
Rea Magnet Wire · Sep 18, 2023
RTA · Sep 18, 2023
TSC · Sep 18, 2023
PASCHAL - Werk G Maier · Sep 18, 2023
Vucke · Sep 18, 2023
Dpc & S · Sep 13, 2023
Carpet One · Sep 13, 2023
Markentrainer Werbeagentur, Elwema Automotive · Sep 13, 2023
Precisely, Winshuttle · Sep 6, 2023
Kikkerland Design · Sep 6, 2023
Markentrainer Werbeagentur · Sep 6, 2023
Master Interiors · Sep 6, 2023
Bordelon Marine · Sep 6, 2023
Majestic Spice · Sep 6, 2023
Firmdale Hotels · Sep 5, 2023
F??????? ?????s · Sep 1, 2023
Alfagomma, Argus Fluidhandling Ltd · Aug 26, 2023
A???? F??????????? Ltd · Aug 23, 2023
ABS Auto Auctions · Aug 19, 2023
DSA Law Pty Ltd · Aug 19, 2023
Miami Management · Aug 19, 2023
BTC Power · Aug 19, 2023
Stanford Transportation Inc · Aug 19, 2023
Bolton Group · Aug 19, 2023
Legends Limousine · Aug 19, 2023
Oneonline · Aug 19, 2023
Top Light · Aug 11, 2023
Algorry Zappia & Associates · Aug 11, 2023
EAI · Aug 11, 2023
Garage Living, The Dispenser USA · Aug 1, 2023
Aapd · Aug 1, 2023
Birch, Horton, Bittner & Cherot · Aug 1, 2023
DAL-TECH Engineering · Aug 1, 2023
Coral Resort · Aug 1, 2023
Professionnel France · Aug 1, 2023
ACTIVA Group · Aug 1, 2023
Aquatlantis · Aug 1, 2023

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .