Nordkoreanische Hacker ebnen den Weg für Play-Ransomware

Teilen:

North Korean state-sponsored hackers – Jumpy Pisces, aka Andariel, aka Onyx Sleet – have been spotted burrowing into enterprise systems, then seemingly handing matters over to the Play ransomware group.

The attack

The ransomware attack was investigated by Palo Alto Networks’ Unit 42 in September 2024, and they determined that North Korean hackers:

  • Gained access to a host using a compromised users account
  • Moved laterally to other hosts via SMB protocol
  • Maintained persistence via Sliver (a Cobalt Strike alternative) and tried to install DTrack (custom malware that was ultimately blocked by the EDR)
  • Gathered system and network configurations, established RDP sessions via a newly created privileged user account on victim machines, used Mimikatz and a trojanized binary to dump credential logs and steal browser info (history, autofills and credit card details)

“In early September, an unidentified threat actor entered the network through the same compromised user account used by Jumpy Pisces. They carried out pre-ransomware activities including credential harvesting, privilege escalation and the uninstallation of EDR sensors, which eventually led to the deployment of Play ransomware,” Unit 42 researchers explained.

The use of the same compromised account account, the stopping of Sliver C2 communication the day before ransomware deployment, and the use of specific tactics, techniques, and procedures (TTPs) points to “a degree of collaboration between Jumpy Pisces and Play Ransomware.”

But whether Jumpy Pisces has officially become an affiliate for Play ransomware or they simply acted as an initial access broker (IAB) is unclear.

“We expect their attacks will increasingly target a wide range of victims globally. Network defenders should view Jumpy Pisces activity as a potential precursor to ransomware attacks, not just espionage, underscoring the need for heightened vigilance,” the threat analysts concluded.

A trend in the making?

This is not the first time that security researchers discovered state-sponsored hackers helping ransomware groups.

Earlier this year, US security agencies warned about Pioneer Kitten – an Iranian state-contracted cyber espionage group – serving as an initial access provider for NoEscape, RansomHouse, and ALPHV ransomware affiliates, and helping them “enable encryption operations in exchange for a percentage of the ransom payments.”

Microsoft has also noted in its recently released Digital Defense Report that the lines between nation-state and cybercriminal threat activity are becoming increasingly blurred, and that North Korean, Russian and Iranian state-sponsored threat actors are increasingly deploying ransomware for their own (and their states’) financial gain.

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
12:16 pm, Juni 22, 2025
Wetter-Symbol 25°C
L: 24° | H: 27°
wenige Wolken
Luftfeuchtigkeit: 50 %
Druck: 1013 mb
Wind: 15 mph WSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 20%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:43 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
24° | 27°°C 0 mm 0% 17 mph 64 % 1013 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
15° | 23°°C 0.2 mm 20% 15 mph 81 % 1016 mb 0 mm/h
Di. Juni 24 10:00 pm
Wetter-Symbol
14° | 26°°C 0 mm 0% 16 mph 77 % 1015 mb 0 mm/h
Mi. Juni 25 10:00 pm
Wetter-Symbol
16° | 27°°C 0 mm 0% 9 mph 86 % 1013 mb 0 mm/h
Do. Juni 26 10:00 pm
Wetter-Symbol
17° | 24°°C 1 mm 100% 15 mph 95 % 1018 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
24° | 25°°C 0 mm 0% 15 mph 50 % 1013 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
21° | 24°°C 0 mm 0% 17 mph 48 % 1013 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
21° | 22°°C 0 mm 0% 13 mph 54 % 1012 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
16° | 16°°C 0 mm 0% 10 mph 64 % 1012 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
16° | 16°°C 0 mm 0% 13 mph 76 % 1011 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
16° | 16°°C 0.2 mm 20% 13 mph 81 % 1011 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
15° | 15°°C 0.2 mm 20% 13 mph 60 % 1013 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
17° | 17°°C 0 mm 0% 13 mph 46 % 1014 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€89,031.24
-1.18%
Ethereum(ETH)
€1,965.73
-7.17%
Fesseln(USDT)
€0.87
0.01%
XRP(XRP)
€1.77
-4.82%
Solana(SOL)
€115.85
-6.21%
USDC(USDC)
€0.87
-0.01%
Dogecoin(DOGE)
€0.134977
-5.00%
Shiba Inu(SHIB)
€0.000010
-4.87%
Pepe(PEPE)
€0.000008
-8.99%
Peanut das Eichhörnchen(PNUT)
€0.218233
13.10%
Nach oben scrollen