North Korea's Andariel Pivots to 'Play' Ransomware Games
ID: 646e1c8c-91b7-55c9-abb4-f7a73014d045
STIX ID: report--646e1c8c-91b7-55c9-abb4-f7a73014d045
Feed Name: Dark Reading
Threat Score
Date Published: 2024-10-31
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
...
...
Unit 42 reports that North Korea-linked APT Andariel has been observed collaborating with the Play ransomware group—likely acting as an initial access broker—using compromised user accounts, Sliver and custom DTrack malware, SMB-based lateral movement, and EDR removal to ultimately deploy Play ransomware; the report includes IoCs and urges heightened vigilance across targeted sectors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
