ZeroHour

play

ransomware group · aka Play, PlayCrypt, Water Curupira Pikapilya (Trend Micro tracking name) · unknown; widely assessed as likely Russia-based, though no confirmed attribution · active since 2022

Victims · 7d
2flat
Victims · 30d
11active targets
Victims · 90d
44
All-time (tracked)
1.3Ksince 2022-11-26
Last post
09-10 21:44UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Play (PlayCrypt) is a double-extortion ransomware group first publicly documented in 2022, known for a leak-first extortion model, distinctive ransom notes that omit ransom amounts and contact details, and encryption support for Windows, Linux, and FreeBSD. Victim sectors reported include government facilities, critical infrastructure, education facilities, information technology, healthcare/public health, financial services, and manufacturing, across North America, South America, and Europe. Per the FBI/CISA #StopRansomware advisory update (December 2024), Play had affected approximately 900 organizations worldwide, up from about 300 as of July 2023. The group gains access by exploiting known vulnerabilities in internet-facing appliances and remote-monitoring/management (RMM) software, supplemented by valid-account use. Dashboard tracking: 2 victims in the last 7/30/90 days, 2 total since 2026-09-09; last post 2026-09-09.

Tactics & tooling
  • Exploits known vulnerabilities in Fortinet devices for initial access (CVE-2018-13379, CVE-2020-12812, CVE-2020-15310) per FBI/CISA advisory (2024 update)
  • Exploited SimpleHelp RMM path-traversal flaw CVE-2024-5776 as an access vector per FBI/CISA advisory (January 2025)
  • Uses valid accounts, RDP, and RMM/remote-access tooling for lateral movement and persistence
  • Living-off-the-land operations: GPO and scheduled-task deployment, disabling Microsoft Defender, use of batch/PowerShell tooling (FBI/CISA, 2023)
  • Exfiltrates victim data before encryption; reported use of rsync for data transfer
  • Double extortion via Tor-based 'Play News' leak site; ransom notes characteristically lack ransom amount and initial contact information
  • Encrypts across Windows, Linux, and FreeBSD systems
Targeted sectors
GovernmentCritical infrastructureEducationInformation technologyHealthcare/public healthFinancial servicesManufacturing
Notable public victims

Dallas County, Texas (2023; attribution via widely reported press coverage), Red Star Oil (leak-site post tracked by this dashboard, posted 2026-09-09), GT Distributors (leak-site post tracked by this dashboard, posted 2026-09-09)

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
McCarter Electrical · Sep 15, 2025
Pathfinder · Sep 15, 2025
General Control Systems · Sep 15, 2025
RFI · Sep 15, 2025
Crestone Group · Sep 15, 2025
TerranearPMC · Sep 15, 2025
Rochester Optical · Sep 15, 2025
Baum Precision Machining · Sep 15, 2025
HD Media Systems · Sep 10, 2025
Mayors Machine Works · Sep 10, 2025
JIT Energy Services · Sep 10, 2025
Anderson Aluminum · Sep 10, 2025
Royal Machine & Tool · Sep 10, 2025
Reliable Roofing · Sep 10, 2025
Celtic Engineering · Sep 10, 2025
GDZ Computer Services · Sep 10, 2025
Cool Wind Ventilation · Sep 10, 2025
Rising Star Hydraulics · Sep 10, 2025
Edwards Interiors · Sep 10, 2025
GL Veneer · Sep 10, 2025
Energy Fishing · Sep 9, 2025
BDE Computer Services · Sep 9, 2025
Promark Partners · Sep 9, 2025
Arboris · Sep 1, 2025
Juggernaut · Sep 1, 2025
Vanderpool Construction · Sep 1, 2025
All States Materials Group · Sep 1, 2025
Logan & Mencuccini · Aug 26, 2025
Edward J McKarski · Aug 26, 2025
Banville Wine Merchants · Aug 26, 2025
Galaxy Freightline · Aug 26, 2025
Premier Realty Group · Aug 26, 2025
CBG Surveying Texas · Aug 20, 2025
Omega Global Technologies · Aug 20, 2025
ABcom · Aug 14, 2025
Greenscape Pump Services · Aug 14, 2025
eShipGlobal · Aug 14, 2025
NextLabs · Aug 14, 2025
The Scharine Group · Aug 11, 2025
Bluewater Yacht Sales · Aug 11, 2025
Travancore Analytics · Aug 11, 2025
Rite Track · Aug 11, 2025
NEAS · Aug 9, 2025
RHI Supply · Aug 9, 2025
CFI Tire Service · Aug 9, 2025
Jamco Aerospace · Aug 6, 2025
Emprise · Aug 6, 2025
Brad's Bedding Plants · Aug 6, 2025
The Magni Group · Aug 6, 2025
Phoenix Lighting · Aug 4, 2025

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .