Jumpy Pisces Engages in Play Ransomware
2024-10-30 • Paloalto Networks •
https://unit42.paloaltonetworks.com/north-korean-threat-group-play-ransomware/
Unit 42 linked Jumpy Pisces, also known as Andariel or PLUTONIUM, to an intrusion that preceded Play ransomware deployment and assessed with moderate confidence that the North Korean state-sponsored group collaborated with Play ransomware operators or acted as an initial access broker. Investigators found that Jumpy Pisces gained access through a compromised user account in May 2024, then used SMB to spread Sliver and DTrack across hosts while maintaining C2 communication until shortly before ransomware deployment in September. Pre-ransomware activity later included credential harvesting, privilege escalation, EDR sensor uninstallation, Windows access-token abuse, PsExec use, and Play ransomware execution. Reported infrastructure and artifacts included Sliver C2 at americajobmail[.]site and 172.96.137[.]224, DTrack, Mimikatz, a browser-data stealer, and invalid code-signing certificates previously linked to Jumpy Pisces. The case matters because Unit 42 describes it as the first observed Jumpy Pisces use of existing ransomware infrastructure, expanding the group’s relevance from espionage and custom ransomware to broader ransomware operations.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | f64dab23c50e3d131abcc1bdbb35ce9… | 2024-10-02 | 2024-12-13 |
| HASH | b1ac26dac205973cd1288a38265835e… | 2024-10-30 | 2024-10-31 |
| IPv4 | 172.96.137.224 | 2024-10-02 | 2024-10-31 |
| HASH | b4f5d37732272f18206242ccd00f6ca… | 2024-10-30 | 2024-10-30 |
| HASH | 99e2ebf8cec6a0cea57e591ac1ca56d… | 2024-10-30 | 2024-10-30 |
| HASH | 6e95d94d5d8ed2275559256c5fb5fc6… | 2024-10-30 | 2024-10-30 |
| HASH | 2b254ae6690c9e37fa7d249e8578ee2… | 2024-10-02 | 2024-10-30 |
| HASH | 243ad5458706e5c836f8eb88a9f67e1… | 2024-10-02 | 2024-10-30 |
| HASH | 76cb5d1e6c2b6895428115705d9ac765 | 2024-07-25 | 2024-10-30 |
| HASH | 6624c7b8faac176d1c1cb10b03e7ee5… | 2024-07-25 | 2024-10-30 |
| HASH | 879fa942f9f097b74fd6f7dabcf1745a | 2023-02-02 | 2024-10-30 |