the Maiden of Anguish
First seen: 2017-07 •
Last seen: 2026-05
#Play • 2024-10
Unit 42 linked Jumpy Pisces, also known as Andariel or PLUTONIUM, to an intrusion that preceded Play ransomware deployment and assessed with moderate confidence that the North Korean state-sponsored actor collaborated with Play operators or acted as an initial access broker. The activity began with a compromised user account, then used SMB to spread Sliver and DTrack, maintained C2 until shortly before ransomware execution, and included credential harvesting, privilege escalation, EDR sensor removal, Windows access-token abuse, PsExec use, and Play ransomware deployment.
7
Related Reports
0
Affected Countries
20
Months Since
the Maiden of Anguish