216.73.216.6

Play Ransomware Engagement

· Published 30/10/2024 16:32 · Modified 30/10/2024 22:33

Export JSON

Essential information

Published
30/10/2024 16:32
Modified
30/10/2024 22:33
Tags
2024-10-30 dtrack fiddling scorpius initial access broker korean people's army mimikatz north korea play play ransomware reconnaissance general bureau sliver
Related entities
1 intrusion sets (apt), 17 techniques (mitre), 3 malware

Description

Unit 42 has identified Jumpy Pisces, a North Korean state-sponsored threat group, as a key player in a recent ransomware incident. The group appears to be collaborating with the group, marking a shift in their tactics. This is the first observed instance of Jumpy Pisces using existing ransomware infrastructure, potentially acting as an or an affiliate. The attack timeline spans from May to September 2024, involving initial access through a compromised user account, lateral movement, and persistence using tools like and . The incident culminated in the deployment of in early September. This collaboration signals deeper involvement of North Korean threat actors in the broader ransomware landscape, potentially leading to more widespread and damaging attacks globally.

External references