ZeroHour

play

ransomware group · aka Play, PlayCrypt, Water Curupira Pikapilya (Trend Micro tracking name) · unknown; widely assessed as likely Russia-based, though no confirmed attribution · active since 2022

Victims · 7d
2flat
Victims · 30d
11active targets
Victims · 90d
44
All-time (tracked)
1.3Ksince 2022-11-26
Last post
09-10 21:44UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Play (PlayCrypt) is a double-extortion ransomware group first publicly documented in 2022, known for a leak-first extortion model, distinctive ransom notes that omit ransom amounts and contact details, and encryption support for Windows, Linux, and FreeBSD. Victim sectors reported include government facilities, critical infrastructure, education facilities, information technology, healthcare/public health, financial services, and manufacturing, across North America, South America, and Europe. Per the FBI/CISA #StopRansomware advisory update (December 2024), Play had affected approximately 900 organizations worldwide, up from about 300 as of July 2023. The group gains access by exploiting known vulnerabilities in internet-facing appliances and remote-monitoring/management (RMM) software, supplemented by valid-account use. Dashboard tracking: 2 victims in the last 7/30/90 days, 2 total since 2026-09-09; last post 2026-09-09.

Tactics & tooling
  • Exploits known vulnerabilities in Fortinet devices for initial access (CVE-2018-13379, CVE-2020-12812, CVE-2020-15310) per FBI/CISA advisory (2024 update)
  • Exploited SimpleHelp RMM path-traversal flaw CVE-2024-5776 as an access vector per FBI/CISA advisory (January 2025)
  • Uses valid accounts, RDP, and RMM/remote-access tooling for lateral movement and persistence
  • Living-off-the-land operations: GPO and scheduled-task deployment, disabling Microsoft Defender, use of batch/PowerShell tooling (FBI/CISA, 2023)
  • Exfiltrates victim data before encryption; reported use of rsync for data transfer
  • Double extortion via Tor-based 'Play News' leak site; ransom notes characteristically lack ransom amount and initial contact information
  • Encrypts across Windows, Linux, and FreeBSD systems
Targeted sectors
GovernmentCritical infrastructureEducationInformation technologyHealthcare/public healthFinancial servicesManufacturing
Notable public victims

Dallas County, Texas (2023; attribution via widely reported press coverage), Red Star Oil (leak-site post tracked by this dashboard, posted 2026-09-09), GT Distributors (leak-site post tracked by this dashboard, posted 2026-09-09)

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
Super Quik · Oct 28, 2025
Fast Freight · Oct 28, 2025
Aphase II · Oct 28, 2025
Kitchen Design Concepts · Oct 28, 2025
Furniture Plus · Oct 28, 2025
Ouranos · Oct 28, 2025
Sylvester Roofing · Oct 28, 2025
LaBonne · Oct 26, 2025
Metal Pros · Oct 26, 2025
Nelligan White Architects · Oct 21, 2025
National Coatings · Oct 21, 2025
Accord Carton · Oct 19, 2025
Cottage · Oct 17, 2025
BMP Worldwide · Oct 16, 2025
Cellucap Manufacturing · Oct 15, 2025
Global Shop Solutions · Oct 15, 2025
Legacy Manufacturing · Oct 15, 2025
Koch & White Heating & Cooling · Oct 15, 2025
Royal Thai · Oct 15, 2025
Accelerated · Oct 9, 2025
Elmer W. Davis · Oct 9, 2025
AES Clean Technology · Oct 6, 2025
Dataforth · Oct 6, 2025
Waterborne Environmental · Oct 3, 2025
Komar Industries · Sep 30, 2025
Amelia Overhead Doors · Sep 27, 2025
Pangborn · Sep 27, 2025
ComTec Systems · Sep 27, 2025
Earthadelic · Sep 27, 2025
Steve Basso Plumbing Heating · Sep 27, 2025
Atlas Pressed Metals · Sep 27, 2025
Takeuchi US · Sep 22, 2025
DHM Properties · Sep 22, 2025
Vcinity · Sep 22, 2025
GrammaTech · Sep 22, 2025
APG · Sep 22, 2025
Roth & Scholl · Sep 22, 2025
New England Waterproofing · Sep 22, 2025
Combined Services HVAC · Sep 22, 2025
PTR · Sep 22, 2025
Agility CIS · Sep 22, 2025
Hilldun · Sep 22, 2025
Ronco Safety · Sep 22, 2025
United Machine · Sep 19, 2025
Thomas Safran & Associates · Sep 17, 2025
RGR Sportswear · Sep 15, 2025
Lake Book Manufacturing · Sep 15, 2025
Eau Palm Beach Resort & Spa · Sep 15, 2025
Energenecs · Sep 15, 2025
Garrison Architects · Sep 15, 2025

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .