logo

Jumpy Pisces Engages in Play Ransomware

ID: 495c93fd-31b2-5a02-94e9-74f231005836

STIX ID: report--495c93fd-31b2-5a02-94e9-74f231005836

Feed Name: Palo Alto Networks Unit 42

Threat Score
90/100

Date Published: 2024-10-30

Date Updated: 2026-04-28

Author: Unit 42

...
...

**Executive Summary:** Unit 42 attributes a May–September 2024 intrusion to North Korean state-sponsored group Jumpy Pisces that used Sliver and DTrack to maintain access and perform credential harvesting and lateral movement, after which Play ransomware was deployed; the report documents tooling, indicators (SHA256 hashes, C2 IP 172.96.137.224, domain americajobmail.site, and code-sign certificate details), and assesses a likely collaboration or initial-access brokering relationship between Jumpy Pisces and Play ransomware actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.