logo

North Korean govt hackers linked to Play ransomware attack

ID: 3211132f-7dda-5a08-918f-27bbbb2a1818

STIX ID: report--3211132f-7dda-5a08-918f-27bbbb2a1818

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2024-10-30

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

**Unit 42 links North Korea’s Andariel to a Play ransomware incident:** Andariel gained initial access in May 2024 via a compromised account, performed credential harvesting (Mimikatz), deployed Sliver C2 and DTrack across hosts, removed EDR and persisted, and the Play ransomware encryptor was executed in September 2024; researchers assess a likely connection (affiliate or IAB) and note this model helps sanctioned actors evade restrictions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.