Play Ransomware and North Korean APT45 Work Together to Launch Major Cyberattack – Active IOCs

2024-10-31 Rewterz

https://www.rewterz.com/threat-advisory/play-ransomware-and-north-korean-apt45-work-together-to-launch-major-cyberattack-active-iocs

Thumbnail for Play Ransomware and North Korean APT45 Work Together to Launch Major Cyberattack – Active IOCs

APT45, also known as Andariel or Jumpy Pisces, is described as a North Korean state-sponsored actor tied to financially motivated activity involving the Play ransomware operation between May and September 2024. The excerpt says researchers assessed with moderate confidence that Jumpy Pisces, or a faction of it, was collaborating with Play, making the case notable because of the apparent overlap between a North Korean state actor and an underground ransomware network. Initial access was reportedly obtained through a compromised user account, followed by lateral movement and persistence using the Sliver C2 framework and the Dtrack backdoor. Before Play ransomware deployment, actors using the same compromised account performed credential harvesting, privilege escalation, EDR sensor removal, and browser-data theft against the victim environment. Listed IOCs include americajobmail.site and several hashes, giving defenders concrete artifacts to hunt alongside the account and remote-tool activity.

Indicators of Compromise

Type Value First Seen Last Seen
HASH f64dab23c50e3d131abcc1bdbb35ce9… 2024-10-02 2024-12-13
HASH 540853beffb0ba9b26cf305bcf92fad… 2024-10-31 2024-10-31
HASH e12f93d462a622f32a4ff1e646549c42 2024-10-31 2024-10-31
HASH f01eae4ee3cc03d621be7b0af7d60411 2024-10-31 2024-10-31
HASH e3069713add2d99750af6c30580fb35… 2024-10-31 2024-10-31
HASH b1ac26dac205973cd1288a38265835e… 2024-10-30 2024-10-31
IPv4 172.96.137.224 2024-10-02 2024-10-31

Related Actors

Related Reports

« Back