Daily Dark Web
  • Home
  • Data Breaches
  • Inside the Adversary
    • Dark Web Informants
  • DDW Top Lists
  • Ransomware News
  • DarkWeb News
    • Vulnerability
    • Cyber Attacks
  • Unauthorized Accesses
  • About Us
No Result
View All Result
  • Home
  • Data Breaches
  • Inside the Adversary
    • Dark Web Informants
  • DDW Top Lists
  • Ransomware News
  • DarkWeb News
    • Vulnerability
    • Cyber Attacks
  • Unauthorized Accesses
  • About Us
No Result
View All Result
Daily Dark Web
No Result
View All Result
Home Ransomware News

Unit42 Detected Possible Collaboration Between North Korea and Play Ransomware

October 31, 2024
Reading Time: 2 mins read
Unit42 Detected Possible Collaboration Between North Korea and Play Ransomware

Play ransomware, first detected in mid-2022, is linked to a threat group identified as “Fiddling Scorpius,” which is suspected to manage both the development and execution of attacks using the ransomware. Contrary to speculation that Fiddling Scorpius may have adopted a ransomware-as-a-service (RaaS) model, the group asserted on its Play ransomware leak site that it operates independently, without providing RaaS services.

In September 2024, Unit 42 responded to a Play ransomware incident impacting one of their clients. Through Unit 42’s investigation, it was confirmed with high confidence that Jumpy Pisces, a North Korean state-sponsored threat group, gained initial access to the network in May 2024 via a compromised user account. This entry point enabled Jumpy Pisces to perform lateral movement and establish persistence, employing the open-source tool Sliver and their custom malware, DTrack. Both tools were distributed to multiple hosts through the Server Message Block (SMB) protocol, maintaining communication with their command-and-control (C2) servers up until the ransomware deployment in early September.

Analysis of Potential Collaboration
Based on Unit 42’s observations, moderate confidence is placed in the likelihood of collaboration between Jumpy Pisces and Play ransomware. The compromised account initially accessed by Jumpy Pisces was later leveraged for Windows access token abuse and SYSTEM privilege escalation through PsExec, ultimately leading to the uninstallation of EDR sensors and ransomware deployment. Notably, Sliver C2 communication continued until the day before the ransomware attack, and the associated IP address went offline immediately after the ransomware deployment, supporting a potential link.

While it is uncertain if Jumpy Pisces acted as an affiliate or simply as an initial access broker (IAB) selling network access to the ransomware operators, this event highlights a notable collaboration between a state-sponsored North Korean group and an underground ransomware network. This alignment could suggest an emerging trend of North Korean groups joining global ransomware campaigns, potentially leading to broader, more destructive attacks on a global scale.

Full research.

Tags: collaborationNorth KoreaPlayRansomwareRaaSransomwarestateState sponsored
ShareTweet

Related Posts

Qilin Ransomware: Inspira, Muller, A&A, Longwood, Exclusive, Istarpal
Ransomware News

Qilin Ransomware: Inspira, Muller, A&A, Longwood, Exclusive, Istarpal

April 27, 2026
Narteks Tekstil A.S. Suffers Krybit Ransomware Attack
Ransomware News

Narteks Tekstil A.S. Suffers Krybit Ransomware Attack

April 27, 2026
Synmosa Biopharma Hit by Dragonforce Ransomware Attack
Ransomware News

Synmosa Biopharma Hit by Dragonforce Ransomware Attack

April 27, 2026
K2 Electric Inc Targeted in Genesis Ransomware Attack
Ransomware News

K2 Electric Inc Targeted in Genesis Ransomware Attack

April 22, 2026
Rutan & Tucker Law Firm Suffers Data Breach by Silentransomgroup
Ransomware News

Rutan & Tucker Law Firm Suffers Data Breach by Silentransomgroup

April 22, 2026
Qilin Breach: Sea Air, Kolin, INDCAR, PTS, Huonker, Ferguson, SEL, Sterimed, Avitrans, Rusk
Ransomware News

Qilin Breach: Sea Air, Kolin, INDCAR, PTS, Huonker, Ferguson, SEL, Sterimed, Avitrans, Rusk

April 22, 2026
Next Post
Interbank Confirms Data Breach

Interbank Confirms Data Breach

RENIEC Allegedly Breached 37M Citizen Data Leaked

RENIEC Allegedly Breached 37M Citizen Data Leaked

Recommended Stories

Lynx Ransomware Breaches Keller Polska & Africa Insurance

Lynx Ransomware Breaches Keller Polska & Africa Insurance

March 13, 2026
Alleged Access Sale to a US Based Logistics Company

Alleged Access Sale to a US Based Logistics Company

August 12, 2024
10bis Data Breach Exposes 1.4 Million User Records

10bis Data Breach Exposes 1.4 Million User Records

April 17, 2026

Popular Stories

  • SudamericaData Breach Exposes Over 1TB of Argentine Records

    SudamericaData Breach Exposes Over 1TB of Argentine Records

    0 shares
    Share 0 Tweet 0
  • Threat Actor Claims Sale of Dell Database Containing 49 Million Customer Records

    0 shares
    Share 0 Tweet 0
  • SUUMO, CHINTAI, At Home, HOME’S Suffer Data Breach

    0 shares
    Share 0 Tweet 0
  • Financial Tech Giant SilverLake Axis Allegedly Breached – 423GB of Data for Sale

    0 shares
    Share 0 Tweet 0
  • Telekom Serbia Investigates Leak of 160,000 Customer Records

    0 shares
    Share 0 Tweet 0
Daily Dark Web

Disclaimer: Daily Dark Web (DDW) is an independent media platform providing information, analysis, and reporting on cybersecurity, cyber incidents, and related digital developments. All content published on this website is for informational and journalistic purposes only. DDW does not support, endorse, or promote any illegal activities, threat actors, or organizations referenced in its content. Any statements, claims, or opinions expressed by third parties, including interview subjects, are their own and do not reflect the views of DDW. Such content may include unverified information and should be interpreted critically. DDW does not participate in, facilitate, or coordinate any activities discussed or referenced on this platform. Under no circumstances should any content be interpreted as encouragement, instruction, or endorsement of unlawful actions. All interactions and publications are conducted in the public interest to enhance awareness and understanding of the evolving cyber landscape.

No Result
View All Result
  • About Us
  • Home
  • Newsletter
  • Privacy Policy

Disclaimer: Daily Dark Web (DDW) is an independent media platform providing information, analysis, and reporting on cybersecurity, cyber incidents, and related digital developments. All content published on this website is for informational and journalistic purposes only. DDW does not support, endorse, or promote any illegal activities, threat actors, or organizations referenced in its content. Any statements, claims, or opinions expressed by third parties, including interview subjects, are their own and do not reflect the views of DDW. Such content may include unverified information and should be interpreted critically. DDW does not participate in, facilitate, or coordinate any activities discussed or referenced on this platform. Under no circumstances should any content be interpreted as encouragement, instruction, or endorsement of unlawful actions. All interactions and publications are conducted in the public interest to enhance awareness and understanding of the evolving cyber landscape.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?