Play Ransomware and North Korean APT45 Work Together to Launch Major Cyberattack – Active IOCs
2024-10-31 • Rewterz •
APT45, also known as Andariel or Jumpy Pisces, is described as a North Korean state-sponsored actor tied to financially motivated activity involving the Play ransomware operation between May and September 2024. The excerpt says researchers assessed with moderate confidence that Jumpy Pisces, or a faction of it, was collaborating with Play, making the case notable because of the apparent overlap between a North Korean state actor and an underground ransomware network. Initial access was reportedly obtained through a compromised user account, followed by lateral movement and persistence using the Sliver C2 framework and the Dtrack backdoor. Before Play ransomware deployment, actors using the same compromised account performed credential harvesting, privilege escalation, EDR sensor removal, and browser-data theft against the victim environment. Listed IOCs include americajobmail.site and several hashes, giving defenders concrete artifacts to hunt alongside the account and remote-tool activity.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | f64dab23c50e3d131abcc1bdbb35ce9… | 2024-10-02 | 2024-12-13 |
| HASH | 540853beffb0ba9b26cf305bcf92fad… | 2024-10-31 | 2024-10-31 |
| HASH | e12f93d462a622f32a4ff1e646549c42 | 2024-10-31 | 2024-10-31 |
| HASH | f01eae4ee3cc03d621be7b0af7d60411 | 2024-10-31 | 2024-10-31 |
| HASH | e3069713add2d99750af6c30580fb35… | 2024-10-31 | 2024-10-31 |
| HASH | b1ac26dac205973cd1288a38265835e… | 2024-10-30 | 2024-10-31 |
| IPv4 | 172.96.137.224 | 2024-10-02 | 2024-10-31 |