Jumpy Pisces Engages in Play Ransomware

2024-10-30 Paloalto Networks

https://unit42.paloaltonetworks.com/north-korean-threat-group-play-ransomware/

Thumbnail for Jumpy Pisces Engages in Play Ransomware

Unit 42 linked Jumpy Pisces, also known as Andariel or PLUTONIUM, to an intrusion that preceded Play ransomware deployment and assessed with moderate confidence that the North Korean state-sponsored group collaborated with Play ransomware operators or acted as an initial access broker. Investigators found that Jumpy Pisces gained access through a compromised user account in May 2024, then used SMB to spread Sliver and DTrack across hosts while maintaining C2 communication until shortly before ransomware deployment in September. Pre-ransomware activity later included credential harvesting, privilege escalation, EDR sensor uninstallation, Windows access-token abuse, PsExec use, and Play ransomware execution. Reported infrastructure and artifacts included Sliver C2 at americajobmail[.]site and 172.96.137[.]224, DTrack, Mimikatz, a browser-data stealer, and invalid code-signing certificates previously linked to Jumpy Pisces. The case matters because Unit 42 describes it as the first observed Jumpy Pisces use of existing ransomware infrastructure, expanding the group’s relevance from espionage and custom ransomware to broader ransomware operations.

Indicators of Compromise

Type Value First Seen Last Seen
HASH f64dab23c50e3d131abcc1bdbb35ce9… 2024-10-02 2024-12-13
HASH b1ac26dac205973cd1288a38265835e… 2024-10-30 2024-10-31
IPv4 172.96.137.224 2024-10-02 2024-10-31
HASH b4f5d37732272f18206242ccd00f6ca… 2024-10-30 2024-10-30
HASH 99e2ebf8cec6a0cea57e591ac1ca56d… 2024-10-30 2024-10-30
HASH 6e95d94d5d8ed2275559256c5fb5fc6… 2024-10-30 2024-10-30
HASH 2b254ae6690c9e37fa7d249e8578ee2… 2024-10-02 2024-10-30
HASH 243ad5458706e5c836f8eb88a9f67e1… 2024-10-02 2024-10-30
HASH 76cb5d1e6c2b6895428115705d9ac765 2024-07-25 2024-10-30
HASH 6624c7b8faac176d1c1cb10b03e7ee5… 2024-07-25 2024-10-30
HASH 879fa942f9f097b74fd6f7dabcf1745a 2023-02-02 2024-10-30

Related Actors

Related Reports

« Back