play
ransomware group · aka Play, PlayCrypt, Water Curupira Pikapilya (Trend Micro tracking name) · unknown; widely assessed as likely Russia-based, though no confirmed attribution · active since 2022
Play (PlayCrypt) is a double-extortion ransomware group first publicly documented in 2022, known for a leak-first extortion model, distinctive ransom notes that omit ransom amounts and contact details, and encryption support for Windows, Linux, and FreeBSD. Victim sectors reported include government facilities, critical infrastructure, education facilities, information technology, healthcare/public health, financial services, and manufacturing, across North America, South America, and Europe. Per the FBI/CISA #StopRansomware advisory update (December 2024), Play had affected approximately 900 organizations worldwide, up from about 300 as of July 2023. The group gains access by exploiting known vulnerabilities in internet-facing appliances and remote-monitoring/management (RMM) software, supplemented by valid-account use. Dashboard tracking: 2 victims in the last 7/30/90 days, 2 total since 2026-09-09; last post 2026-09-09.
- Exploits known vulnerabilities in Fortinet devices for initial access (CVE-2018-13379, CVE-2020-12812, CVE-2020-15310) per FBI/CISA advisory (2024 update)
- Exploited SimpleHelp RMM path-traversal flaw CVE-2024-5776 as an access vector per FBI/CISA advisory (January 2025)
- Uses valid accounts, RDP, and RMM/remote-access tooling for lateral movement and persistence
- Living-off-the-land operations: GPO and scheduled-task deployment, disabling Microsoft Defender, use of batch/PowerShell tooling (FBI/CISA, 2023)
- Exfiltrates victim data before encryption; reported use of rsync for data transfer
- Double extortion via Tor-based 'Play News' leak site; ransom notes characteristically lack ransom amount and initial contact information
- Encrypts across Windows, Linux, and FreeBSD systems
Dallas County, Texas (2023; attribution via widely reported press coverage), Red Star Oil (leak-site post tracked by this dashboard, posted 2026-09-09), GT Distributors (leak-site post tracked by this dashboard, posted 2026-09-09)
No public figure.
Leak-site victims1,282 posts · newest first
| Victim | Discovered | Details |
|---|---|---|
| S?????????? | · Dec 18, 2022 | — |
| Arsat | · Dec 16, 2022 | — |
| JMicron | · Dec 16, 2022 | — |
| VFS | · Dec 13, 2022 | — |
| Cetrogar | · Dec 13, 2022 | — |
| Antwerpen | · Dec 12, 2022 | — |
| Una Seguros | · Dec 12, 2022 | — |
| ??????? | · Dec 9, 2022 | — |
| Hilldrup | · Dec 9, 2022 | — |
| Skoda Praha | · Dec 7, 2022 | — |
| MME Group | · Dec 7, 2022 | — |
| Wrota Mazowsza | · Dec 7, 2022 | — |
| UJV Rez | · Dec 7, 2022 | — |
| Highwater Ethanol | · Dec 7, 2022 | — |
| ????????? ???? ????? | · Dec 7, 2022 | — |
| CIBTvisas | · Dec 6, 2022 | — |
| Austria Presse Agentur | · Dec 5, 2022 | — |
| ??? | · Nov 29, 2022 | — |
| ???? ??? | · Nov 26, 2022 | — |
| ???? | · Nov 26, 2022 | — |
| PVFCCo | · Nov 26, 2022 | — |
| Leadtek | · Nov 26, 2022 | — |
| Alcomet | · Nov 26, 2022 | — |
| Ministry of Transport and Public Works | · Nov 26, 2022 | — |
| Itsgroup | · Nov 26, 2022 | — |
| Conseil departemental - Alpes-Maritimes | · Nov 26, 2022 | — |
| Origin Property Company Limited | · Nov 26, 2022 | — |
| ???? ????? | · Nov 26, 2022 | — |
| Verity cloud | · Nov 26, 2022 | — |
| ??????????? | · Nov 26, 2022 | — |
| ??????? ???? ??????? | · Nov 26, 2022 | — |
| ?????????? | · Nov 26, 2022 | — |
In the newsAll →
No articles mention this group yet.