ZeroHour

play

ransomware group · aka Play, PlayCrypt, Water Curupira Pikapilya (Trend Micro tracking name) · unknown; widely assessed as likely Russia-based, though no confirmed attribution · active since 2022

Victims · 7d
2flat
Victims · 30d
14active targets
Victims · 90d
44
All-time (tracked)
1.3Ksince 2022-11-26
Last post
09-10 21:44UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Play (PlayCrypt) is a double-extortion ransomware group first publicly documented in 2022, known for a leak-first extortion model, distinctive ransom notes that omit ransom amounts and contact details, and encryption support for Windows, Linux, and FreeBSD. Victim sectors reported include government facilities, critical infrastructure, education facilities, information technology, healthcare/public health, financial services, and manufacturing, across North America, South America, and Europe. Per the FBI/CISA #StopRansomware advisory update (December 2024), Play had affected approximately 900 organizations worldwide, up from about 300 as of July 2023. The group gains access by exploiting known vulnerabilities in internet-facing appliances and remote-monitoring/management (RMM) software, supplemented by valid-account use. Dashboard tracking: 2 victims in the last 7/30/90 days, 2 total since 2026-09-09; last post 2026-09-09.

Tactics & tooling
  • Exploits known vulnerabilities in Fortinet devices for initial access (CVE-2018-13379, CVE-2020-12812, CVE-2020-15310) per FBI/CISA advisory (2024 update)
  • Exploited SimpleHelp RMM path-traversal flaw CVE-2024-5776 as an access vector per FBI/CISA advisory (January 2025)
  • Uses valid accounts, RDP, and RMM/remote-access tooling for lateral movement and persistence
  • Living-off-the-land operations: GPO and scheduled-task deployment, disabling Microsoft Defender, use of batch/PowerShell tooling (FBI/CISA, 2023)
  • Exfiltrates victim data before encryption; reported use of rsync for data transfer
  • Double extortion via Tor-based 'Play News' leak site; ransom notes characteristically lack ransom amount and initial contact information
  • Encrypts across Windows, Linux, and FreeBSD systems
Targeted sectors
GovernmentCritical infrastructureEducationInformation technologyHealthcare/public healthFinancial servicesManufacturing
Notable public victims

Dallas County, Texas (2023; attribution via widely reported press coverage), Red Star Oil (leak-site post tracked by this dashboard, posted 2026-09-09), GT Distributors (leak-site post tracked by this dashboard, posted 2026-09-09)

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
Genoa Lakes · Dec 29, 2025
Esquire Brands · Dec 29, 2025
JZ Russell Industries · Dec 29, 2025
MP Filtri · Dec 29, 2025
C&r Electric · Dec 29, 2025
Security ONE Alarm Systems · Dec 20, 2025
Kucera International · Dec 20, 2025
Allure Home Creation · Dec 16, 2025
Fairgrove Oil · Dec 16, 2025
Maypay Farms Inc · Dec 16, 2025
Southern Specialty & Supply · Dec 16, 2025
Jabezco Industrial Group · Dec 13, 2025
Choates HVAC · Dec 13, 2025
Viga Eatery · Dec 13, 2025
Eastman Cooke · Dec 13, 2025
University Loft · Dec 1, 2025
PHA Body Systems · Dec 1, 2025
South Island Public Service District · Dec 1, 2025
Clark & Sullivan Constructors · Dec 1, 2025
Hall Aluminum Products · Dec 1, 2025
Aspen Distribution · Dec 1, 2025
ADC Aerospace · Nov 26, 2025
Katch Kan · Nov 22, 2025
Keystone Fabricating · Nov 22, 2025
Turkstra Trusses · Nov 22, 2025
Radio Sound · Nov 20, 2025
Applied Energy Systems · Nov 20, 2025
Artesian Insurance · Nov 20, 2025
One Source Associates · Nov 20, 2025
N C Machinery · Nov 20, 2025
Highmark Companies · Nov 20, 2025
Valley Plains Equipment · Nov 14, 2025
Sellers Publishing · Nov 14, 2025
BK Precision · Nov 14, 2025
Garvin Promotion Group · Nov 10, 2025
Jean-Georges · Nov 10, 2025
Kwik Mix Materials · Nov 10, 2025
Ioxo & Stream Computers · Nov 10, 2025
Darvin Furniture · Nov 10, 2025
Land Title Guaranty · Nov 10, 2025
ConvExx · Nov 4, 2025
Sellars Absorbent Materials · Nov 4, 2025
American PowerNet · Nov 4, 2025
Irwin Car · Nov 3, 2025
Professional's Choice Sports · Nov 1, 2025
Encore Repair Services · Nov 1, 2025
Tavo Packaging Inc · Nov 1, 2025
Wright Tool · Nov 1, 2025
Henry Raymond & Thompson · Oct 28, 2025
Evogence · Oct 28, 2025

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .