ZeroHour

play

ransomware group · aka Play, PlayCrypt, Water Curupira Pikapilya (Trend Micro tracking name) · unknown; widely assessed as likely Russia-based, though no confirmed attribution · active since 2022

Victims · 7d
0▼4
Victims · 30d
10active targets
Victims · 90d
44
All-time (tracked)
1.3Ksince 2022-11-26
Last post
09-10 21:44UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Play (PlayCrypt) is a double-extortion ransomware group first publicly documented in 2022, known for a leak-first extortion model, distinctive ransom notes that omit ransom amounts and contact details, and encryption support for Windows, Linux, and FreeBSD. Victim sectors reported include government facilities, critical infrastructure, education facilities, information technology, healthcare/public health, financial services, and manufacturing, across North America, South America, and Europe. Per the FBI/CISA #StopRansomware advisory update (December 2024), Play had affected approximately 900 organizations worldwide, up from about 300 as of July 2023. The group gains access by exploiting known vulnerabilities in internet-facing appliances and remote-monitoring/management (RMM) software, supplemented by valid-account use. Dashboard tracking: 2 victims in the last 7/30/90 days, 2 total since 2026-09-09; last post 2026-09-09.

Tactics & tooling
  • Exploits known vulnerabilities in Fortinet devices for initial access (CVE-2018-13379, CVE-2020-12812, CVE-2020-15310) per FBI/CISA advisory (2024 update)
  • Exploited SimpleHelp RMM path-traversal flaw CVE-2024-5776 as an access vector per FBI/CISA advisory (January 2025)
  • Uses valid accounts, RDP, and RMM/remote-access tooling for lateral movement and persistence
  • Living-off-the-land operations: GPO and scheduled-task deployment, disabling Microsoft Defender, use of batch/PowerShell tooling (FBI/CISA, 2023)
  • Exfiltrates victim data before encryption; reported use of rsync for data transfer
  • Double extortion via Tor-based 'Play News' leak site; ransom notes characteristically lack ransom amount and initial contact information
  • Encrypts across Windows, Linux, and FreeBSD systems
Targeted sectors
GovernmentCritical infrastructureEducationInformation technologyHealthcare/public healthFinancial servicesManufacturing
Notable public victims

Dallas County, Texas (2023; attribution via widely reported press coverage), Red Star Oil (leak-site post tracked by this dashboard, posted 2026-09-09), GT Distributors (leak-site post tracked by this dashboard, posted 2026-09-09)

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
John Mulder Heating & Air Conditioning · Jul 24, 2023
Scharco Elektronik · Jul 24, 2023
Primoteq · Jul 24, 2023
Grupo MH · Jul 24, 2023
FERRE BARNIEDO · Jul 24, 2023
Samson Electric · Jul 22, 2023
Kensington Publishing · Jul 19, 2023
Fernmoor Homes · Jul 19, 2023
ECS Technology Group · Jul 19, 2023
Woodbine Hospitality · Jul 19, 2023
Sea Force IX · Jul 19, 2023
Centennial Management · Jul 19, 2023
Lane Valente Industries · Jul 8, 2023
Lazer Tow · Jul 7, 2023
Star Island Resort · Jul 7, 2023
Indiana Dimension · Jul 7, 2023
Lawer SpA · Jul 7, 2023
NST Attorneys at Law · Jul 7, 2023
Uniquify · Jul 7, 2023
Geneva Software · Jul 7, 2023
MUJI Europe Holdings Limited · Jul 7, 2023
Betty Lou's · Jul 7, 2023
Capacity LLC · Jul 7, 2023
Safety Network · Jul 7, 2023
Texas Heat Treating · Jun 28, 2023
Intoximeters · Jun 28, 2023
Algotech · Jun 28, 2023
Cambridge Group of Clubs · Jun 28, 2023
Hill International · Jun 23, 2023
Peter Mark · Jun 21, 2023
Dancie Perugini Ware Public Relations · Jun 21, 2023
Summit Hut · Jun 21, 2023
OMNIPOL · Jun 21, 2023
Hi-tec, Batra Group · Jun 21, 2023
Barentz North America · Jun 21, 2023
PWI Engineering · Jun 21, 2023
Federation Francaise de Rugby · Jun 21, 2023
Luís Simoes · Jun 21, 2023
Allpro Consulting Group · Jun 21, 2023
Lorclon · Jun 21, 2023
Wolfs Block Management Limited · Jun 21, 2023
Globalcaja · Jun 2, 2023
Fortress Paper · Jun 2, 2023
Unico Data,INSYS Industriesysteme,PathA Suisse,PB Swiss Tools,Boess Gruppe · Jun 2, 2023
Alberta Newsprint · Jun 2, 2023
CS Cargo Group · Jun 2, 2023
BMD Systemhaus · Jun 2, 2023
Buffalo Niagara Association · Jun 2, 2023
Abeko · Jun 2, 2023
NORANET - CZ · Jun 2, 2023

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .