ZeroHour

play

ransomware group · aka Play, PlayCrypt, Water Curupira Pikapilya (Trend Micro tracking name) · unknown; widely assessed as likely Russia-based, though no confirmed attribution · active since 2022

Victims · 7d
2flat
Victims · 30d
14active targets
Victims · 90d
44
All-time (tracked)
1.3Ksince 2022-11-26
Last post
09-10 21:44UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Play (PlayCrypt) is a double-extortion ransomware group first publicly documented in 2022, known for a leak-first extortion model, distinctive ransom notes that omit ransom amounts and contact details, and encryption support for Windows, Linux, and FreeBSD. Victim sectors reported include government facilities, critical infrastructure, education facilities, information technology, healthcare/public health, financial services, and manufacturing, across North America, South America, and Europe. Per the FBI/CISA #StopRansomware advisory update (December 2024), Play had affected approximately 900 organizations worldwide, up from about 300 as of July 2023. The group gains access by exploiting known vulnerabilities in internet-facing appliances and remote-monitoring/management (RMM) software, supplemented by valid-account use. Dashboard tracking: 2 victims in the last 7/30/90 days, 2 total since 2026-09-09; last post 2026-09-09.

Tactics & tooling
  • Exploits known vulnerabilities in Fortinet devices for initial access (CVE-2018-13379, CVE-2020-12812, CVE-2020-15310) per FBI/CISA advisory (2024 update)
  • Exploited SimpleHelp RMM path-traversal flaw CVE-2024-5776 as an access vector per FBI/CISA advisory (January 2025)
  • Uses valid accounts, RDP, and RMM/remote-access tooling for lateral movement and persistence
  • Living-off-the-land operations: GPO and scheduled-task deployment, disabling Microsoft Defender, use of batch/PowerShell tooling (FBI/CISA, 2023)
  • Exfiltrates victim data before encryption; reported use of rsync for data transfer
  • Double extortion via Tor-based 'Play News' leak site; ransom notes characteristically lack ransom amount and initial contact information
  • Encrypts across Windows, Linux, and FreeBSD systems
Targeted sectors
GovernmentCritical infrastructureEducationInformation technologyHealthcare/public healthFinancial servicesManufacturing
Notable public victims

Dallas County, Texas (2023; attribution via widely reported press coverage), Red Star Oil (leak-site post tracked by this dashboard, posted 2026-09-09), GT Distributors (leak-site post tracked by this dashboard, posted 2026-09-09)

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
Makivik · Feb 11, 2026
Northbridge · Feb 11, 2026
Milwaukee Forge · Feb 10, 2026
Carlton Scale · Feb 7, 2026
De Gruyter Brill · Feb 7, 2026
ESS Metron · Feb 7, 2026
Ilderton Contracting · Feb 7, 2026
Bloom's Bus Lines · Feb 7, 2026
RAL Companies · Feb 7, 2026
KaiserAir · Feb 7, 2026
ISTS · Feb 4, 2026
CBH Homes · Feb 4, 2026
Woodfield · Feb 4, 2026
Deatak · Feb 1, 2026
Bar S Services · Jan 31, 2026
NAI Plotkin · Jan 31, 2026
Transaction Packing · Jan 31, 2026
Tele Plus · Jan 26, 2026
F&B Mfg · Jan 26, 2026
The Sourcing Group · Jan 26, 2026
ALLMAX · Jan 26, 2026
Quantum Fuel Systems Technologies · Jan 26, 2026
Aquatic Control · Jan 26, 2026
Christine London · Jan 26, 2026
Routten & Laster Law · Jan 26, 2026
Joyva · Jan 26, 2026
TREC Group · Jan 23, 2026
Encore Roofing · Jan 23, 2026
California Tax Data · Jan 22, 2026
CE Electronics · Jan 21, 2026
Cemtech · Jan 21, 2026
Midway Windows and Doors · Jan 21, 2026
Release Marine · Jan 20, 2026
Raymundos Food Group · Jan 20, 2026
Riverwood Golf Club · Jan 20, 2026
Eastern Ice · Jan 20, 2026
Launie & Marino · Jan 12, 2026
Denny's 5th Avenue Bakery · Jan 12, 2026
WiZiX Technology Group · Jan 12, 2026
Autohaus Pichel GmbH · Jan 6, 2026
Due Doyle Fanning · Jan 6, 2026
Mill Brothers · Jan 6, 2026
Lakeside Title Company · Jan 2, 2026
Wardell Builders · Jan 2, 2026
Garner Foods · Jan 2, 2026
Pewarchuk CPA · Jan 2, 2026
Benise-Dowling & Associates · Jan 2, 2026
Rockport Technology Group · Jan 2, 2026
Stoughton Steel · Jan 2, 2026
Infinite Computing Systems · Dec 31, 2025

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .