North Korean threat actor Jumpy Pisces collaborated with the Play ransomware gang in a cyberattack, according to Palo Alto Networks Unit 42. Jumpy Pisces made initial access through a compromised account, utilising open-source and custom tools for lateral movement and persistence. The access was then used to conduct pre-ransomware activity and deploy the Play ransomware payload. Jumpy Pisces, linked to North Korea’s Reconnaissance General Bureau, is transitioning from cyberespionage to financially motivated attacks.

North Korean Hackers Use Fake U.S. Companies to Spread Malware in Crypto Industry: Report
North Korean hackers reportedly set up shell companies in the US to penetrate the crypto sector and target developers via fake job offers, according to