ZeroHour

play

ransomware group · aka Play, PlayCrypt, Water Curupira Pikapilya (Trend Micro tracking name) · unknown; widely assessed as likely Russia-based, though no confirmed attribution · active since 2022

Victims · 7d
2flat
Victims · 30d
11active targets
Victims · 90d
44
All-time (tracked)
1.3Ksince 2022-11-26
Last post
09-10 21:44UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Play (PlayCrypt) is a double-extortion ransomware group first publicly documented in 2022, known for a leak-first extortion model, distinctive ransom notes that omit ransom amounts and contact details, and encryption support for Windows, Linux, and FreeBSD. Victim sectors reported include government facilities, critical infrastructure, education facilities, information technology, healthcare/public health, financial services, and manufacturing, across North America, South America, and Europe. Per the FBI/CISA #StopRansomware advisory update (December 2024), Play had affected approximately 900 organizations worldwide, up from about 300 as of July 2023. The group gains access by exploiting known vulnerabilities in internet-facing appliances and remote-monitoring/management (RMM) software, supplemented by valid-account use. Dashboard tracking: 2 victims in the last 7/30/90 days, 2 total since 2026-09-09; last post 2026-09-09.

Tactics & tooling
  • Exploits known vulnerabilities in Fortinet devices for initial access (CVE-2018-13379, CVE-2020-12812, CVE-2020-15310) per FBI/CISA advisory (2024 update)
  • Exploited SimpleHelp RMM path-traversal flaw CVE-2024-5776 as an access vector per FBI/CISA advisory (January 2025)
  • Uses valid accounts, RDP, and RMM/remote-access tooling for lateral movement and persistence
  • Living-off-the-land operations: GPO and scheduled-task deployment, disabling Microsoft Defender, use of batch/PowerShell tooling (FBI/CISA, 2023)
  • Exfiltrates victim data before encryption; reported use of rsync for data transfer
  • Double extortion via Tor-based 'Play News' leak site; ransom notes characteristically lack ransom amount and initial contact information
  • Encrypts across Windows, Linux, and FreeBSD systems
Targeted sectors
GovernmentCritical infrastructureEducationInformation technologyHealthcare/public healthFinancial servicesManufacturing
Notable public victims

Dallas County, Texas (2023; attribution via widely reported press coverage), Red Star Oil (leak-site post tracked by this dashboard, posted 2026-09-09), GT Distributors (leak-site post tracked by this dashboard, posted 2026-09-09)

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
Backstage Library Works · Aug 4, 2025
White Horse Packaging · Aug 4, 2025
Terillium · Aug 4, 2025
Thern · Jul 31, 2025
Quartus Engineering · Jul 31, 2025
Ka Logistics · Jul 23, 2025
DA Whitacre Construction · Jul 23, 2025
Morrison Companies · Jul 16, 2025
IMSSA Manufacturing · Jul 16, 2025
Hulberg & Associates · Jul 14, 2025
Rockrose Development · Jul 14, 2025
EIA Global · Jul 11, 2025
CyberlinkASP · Jul 11, 2025
FormWood Industries · Jul 11, 2025
Wfmt · Jul 8, 2025
Wood, Patel & Associates · Jul 8, 2025
Tyree Oil · Jul 8, 2025
Lee Publications · Jul 7, 2025
Allied Steel Buildings · Jul 7, 2025
Advance Ready Mix · Jul 7, 2025
Whim Hospitality · Jul 6, 2025
JFC Electric · Jul 3, 2025
Metric · Jul 3, 2025
All Choice Rentals · Jul 3, 2025
Biofloral · Jul 3, 2025
Lydig Construction · Jul 3, 2025
Budget Electric · Jun 29, 2025
Carter Manufacturing · Jun 27, 2025
Emtech Inc · Jun 27, 2025
View Zuellig Industrial · Jun 27, 2025
Islington Golf Club · Jun 27, 2025
Sunrise Springs Spa Resort · Jun 27, 2025
CGP&H · Jun 27, 2025
Cartel Communication Systems · Jun 27, 2025
Associated Packaging · Jun 27, 2025
Merlin Industries · Jun 26, 2025
Fisher59 · Jun 23, 2025
Ovalstrapping · Jun 23, 2025
Dairy Farmers of America · Jun 23, 2025
Vacation Myrtle Beach · Jun 19, 2025
Place Homes · Jun 19, 2025
Jasper Products · Jun 16, 2025
NF Stroth & Associates · Jun 16, 2025
Project Partners · Jun 14, 2025
S&H Express · Jun 14, 2025
Rollex · Jun 14, 2025
NPD Products · Jun 14, 2025
Homestead Gardens · Jun 9, 2025
Community Choice Credit Union · Jun 9, 2025
Ebac · Jun 5, 2025

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .