ZeroHour

play

ransomware group · aka Play, PlayCrypt, Water Curupira Pikapilya (Trend Micro tracking name) · unknown; widely assessed as likely Russia-based, though no confirmed attribution · active since 2022

Victims · 7d
2flat
Victims · 30d
11active targets
Victims · 90d
44
All-time (tracked)
1.3Ksince 2022-11-26
Last post
09-10 21:44UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Play (PlayCrypt) is a double-extortion ransomware group first publicly documented in 2022, known for a leak-first extortion model, distinctive ransom notes that omit ransom amounts and contact details, and encryption support for Windows, Linux, and FreeBSD. Victim sectors reported include government facilities, critical infrastructure, education facilities, information technology, healthcare/public health, financial services, and manufacturing, across North America, South America, and Europe. Per the FBI/CISA #StopRansomware advisory update (December 2024), Play had affected approximately 900 organizations worldwide, up from about 300 as of July 2023. The group gains access by exploiting known vulnerabilities in internet-facing appliances and remote-monitoring/management (RMM) software, supplemented by valid-account use. Dashboard tracking: 2 victims in the last 7/30/90 days, 2 total since 2026-09-09; last post 2026-09-09.

Tactics & tooling
  • Exploits known vulnerabilities in Fortinet devices for initial access (CVE-2018-13379, CVE-2020-12812, CVE-2020-15310) per FBI/CISA advisory (2024 update)
  • Exploited SimpleHelp RMM path-traversal flaw CVE-2024-5776 as an access vector per FBI/CISA advisory (January 2025)
  • Uses valid accounts, RDP, and RMM/remote-access tooling for lateral movement and persistence
  • Living-off-the-land operations: GPO and scheduled-task deployment, disabling Microsoft Defender, use of batch/PowerShell tooling (FBI/CISA, 2023)
  • Exfiltrates victim data before encryption; reported use of rsync for data transfer
  • Double extortion via Tor-based 'Play News' leak site; ransom notes characteristically lack ransom amount and initial contact information
  • Encrypts across Windows, Linux, and FreeBSD systems
Targeted sectors
GovernmentCritical infrastructureEducationInformation technologyHealthcare/public healthFinancial servicesManufacturing
Notable public victims

Dallas County, Texas (2023; attribution via widely reported press coverage), Red Star Oil (leak-site post tracked by this dashboard, posted 2026-09-09), GT Distributors (leak-site post tracked by this dashboard, posted 2026-09-09)

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
Triumph Construction · Jun 5, 2025
Rochon · Jun 3, 2025
Sorter Construction · Jun 3, 2025
Capital Trade · Jun 2, 2025
FLOE Internationa · Jun 2, 2025
Tri-Point Solutions · May 30, 2025
W.E. Bowers · May 30, 2025
Anchor Industries · May 30, 2025
Eliel Cycling · May 28, 2025
KDV Label · May 28, 2025
Frederick's Machine & Tool Shop · May 26, 2025
WAT Supplies · May 26, 2025
Media Links · May 26, 2025
Vernon Milling · May 23, 2025
South Atlantic Federal Credit Union · May 23, 2025
AKJ Energiteknik · May 23, 2025
CNHI LLC · May 21, 2025
AttainX · May 21, 2025
Greater Seattle Concrete · May 21, 2025
K & K Fence · May 19, 2025
Carney Badley Spellman · May 17, 2025
Grafton Technologies · May 14, 2025
Regal Ideas · May 14, 2025
Dishaka · May 14, 2025
Overhead Door of Nova Scotia · May 12, 2025
Operative · May 12, 2025
Just Concrete & Masonry · May 12, 2025
EIZO Rugged Solutions · May 12, 2025
EMX Enterprises · May 9, 2025
Verrex · May 9, 2025
Sweet Shop USA · May 9, 2025
Gistic Research · May 9, 2025
UniTrak · May 8, 2025
ATI Systems · May 5, 2025
Novosit · May 5, 2025
Downtown Travel · May 5, 2025
Rand Technology · May 5, 2025
Alberta Construction Safety Association · May 5, 2025
Breen Construction Services · May 5, 2025
Trybus · May 5, 2025
Sugar Lake Lodge · May 5, 2025
Marine Technical Surveyors · May 5, 2025
Webcor · May 5, 2025
Technical Die-Casting · May 5, 2025
Defected Records · May 1, 2025
ECOM America · May 1, 2025
Southern Fidelity · May 1, 2025
Custom Paper · May 1, 2025
The Seydel Companies · May 1, 2025
National Steel City · May 1, 2025

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .