Play Ransomware and North Korean Hackers: A New Alliance in Cybercrime
Recent reports indicate that North Korean hackers known as Jumpy Pisces have teamed up with the Play ransomware group between May and September 2024. This is notable as it marks the first collaboration between a state-sponsored group from North Korea and a ransomware network.
Jumpy Pisces, associated with North Korea’s Reconnaissance General Bureau, has previously used other ransomware strains. In August, three U.S. organizations were targeted by the group, but no ransomware was deployed at that time.
The Play ransomware operation has affected around 300 organizations and is thought to have shifted to a ransomware-as-a-service model, although the group denies this. Investigations reveal that Jumpy Pisces gained access to networks through a compromised user account, leading to the eventual deployment of Play ransomware.
The attack involved collecting sensitive information from browsers and indicates a troubling trend of collaboration between state-sponsored actors and criminal groups, driven by financial motives.
source: https://thehackernews.com/2024/10/north-korean-group-collaborates-with.html
This is alarming