North Korean threat actor Jumpy Pisces collaborated with the Play ransomware gang in a cyberattack, according to Palo Alto Networks Unit 42. Jumpy Pisces made initial access through a compromised account, utilising open-source and custom tools for lateral movement and persistence. The access was then used to conduct pre-ransomware activity and deploy the Play ransomware payload. Jumpy Pisces, linked to North Korea’s Reconnaissance General Bureau, is transitioning from cyberespionage to financially motivated attacks.

Cambodian compound found with new type of scam malware: researchers – Nikkei Asia
Cambodian compound found with new type of scam malware: researchers Nikkei Asia

