ZeroHour

play

ransomware group · aka Play, PlayCrypt, Water Curupira Pikapilya (Trend Micro tracking name) · unknown; widely assessed as likely Russia-based, though no confirmed attribution · active since 2022

Victims · 7d
0▼4
Victims · 30d
10active targets
Victims · 90d
44
All-time (tracked)
1.3Ksince 2022-11-26
Last post
09-10 21:44UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Play (PlayCrypt) is a double-extortion ransomware group first publicly documented in 2022, known for a leak-first extortion model, distinctive ransom notes that omit ransom amounts and contact details, and encryption support for Windows, Linux, and FreeBSD. Victim sectors reported include government facilities, critical infrastructure, education facilities, information technology, healthcare/public health, financial services, and manufacturing, across North America, South America, and Europe. Per the FBI/CISA #StopRansomware advisory update (December 2024), Play had affected approximately 900 organizations worldwide, up from about 300 as of July 2023. The group gains access by exploiting known vulnerabilities in internet-facing appliances and remote-monitoring/management (RMM) software, supplemented by valid-account use. Dashboard tracking: 2 victims in the last 7/30/90 days, 2 total since 2026-09-09; last post 2026-09-09.

Tactics & tooling
  • Exploits known vulnerabilities in Fortinet devices for initial access (CVE-2018-13379, CVE-2020-12812, CVE-2020-15310) per FBI/CISA advisory (2024 update)
  • Exploited SimpleHelp RMM path-traversal flaw CVE-2024-5776 as an access vector per FBI/CISA advisory (January 2025)
  • Uses valid accounts, RDP, and RMM/remote-access tooling for lateral movement and persistence
  • Living-off-the-land operations: GPO and scheduled-task deployment, disabling Microsoft Defender, use of batch/PowerShell tooling (FBI/CISA, 2023)
  • Exfiltrates victim data before encryption; reported use of rsync for data transfer
  • Double extortion via Tor-based 'Play News' leak site; ransom notes characteristically lack ransom amount and initial contact information
  • Encrypts across Windows, Linux, and FreeBSD systems
Targeted sectors
GovernmentCritical infrastructureEducationInformation technologyHealthcare/public healthFinancial servicesManufacturing
Notable public victims

Dallas County, Texas (2023; attribution via widely reported press coverage), Red Star Oil (leak-site post tracked by this dashboard, posted 2026-09-09), GT Distributors (leak-site post tracked by this dashboard, posted 2026-09-09)

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
Shows & Artists · Jun 2, 2023
Soroc · May 30, 2023
Black Cat Networks · May 23, 2023
Paragon Software Lanka · May 23, 2023
Mayberry Investments · May 23, 2023
Grupo Corporacion Control · May 23, 2023
Studioline Photography · May 23, 2023
Optimus Steel · May 23, 2023
Xplain · May 23, 2023
Royal Centre · May 23, 2023
Poly · May 23, 2023
Aria Online · May 23, 2023
SOWITEC · May 16, 2023
Sauerbruch Hutton · May 11, 2023
JP Maguire & Associates · May 11, 2023
Germany · May 11, 2023
KLC Network Services · May 9, 2023
SIVSA, Coremain · May 4, 2023
Nova Group · May 4, 2023
City of Lowell · May 4, 2023
DGC · May 4, 2023
Libra Virtua · May 4, 2023
Commune de Saxon · May 4, 2023
Negma Business Solutions · May 4, 2023
Vocalcom · May 4, 2023
Woonkracht10 · May 4, 2023
Groupe Gambetta · Apr 22, 2023
UECC · Apr 22, 2023
Bang IT Solutions · Apr 18, 2023
Huissiers · Apr 18, 2023
Coldiretti · Apr 18, 2023
Corrib Oil · Apr 18, 2023
Structab AB (MegTax) · Apr 18, 2023
CH Media · Apr 12, 2023
PESA Bydgoszcz · Apr 11, 2023
Palo Alto County Sheriff · Apr 9, 2023
PKF Antares · Apr 9, 2023
Legion Aero · Apr 9, 2023
Vleeswarenfabriek Jac Michiels · Apr 9, 2023
Schirm · Apr 9, 2023
BMW France · Mar 29, 2023
Oscar Software · Mar 29, 2023
Jablite · Mar 29, 2023
Picou Builders Supply · Mar 27, 2023
Kk Mehta Cpa Associates · Mar 27, 2023
Lightcast · Mar 27, 2023
Optica · Mar 27, 2023
James, McElroy and Diehl · Mar 27, 2023
Lysander Associates · Mar 27, 2023
TAC · Mar 27, 2023

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .