North Korean threat actor Jumpy Pisces collaborated with the Play ransomware gang in a cyberattack, according to Palo Alto Networks Unit 42. Jumpy Pisces made initial access through a compromised account, utilising open-source and custom tools for lateral movement and persistence. The access was then used to conduct pre-ransomware activity and deploy the Play ransomware payload. Jumpy Pisces, linked to North Korea’s Reconnaissance General Bureau, is transitioning from cyberespionage to financially motivated attacks.

ClickFix Captcha – A Creative Technique That Allow Attackers Deliver Malware and Ransomware on Windows
The ClickFix Captcha technique exploits user trust to distribute malware, including Quakbot. Users visiting malicious sites encounter a fake captcha directing them to perform actions