North Korean Andariel Group Linked to Play Ransomware in Unprecedented Nation-State Collaboration

The boundary between nation-state espionage and criminal ransomware operations just got thinner. Anvilogic reports that Palo Alto Networks' Unit 42 has uncovered evidence linking North Korea's Andariel group — also tracked as Jumpy Pisces and Onyx Sleet — to the Play ransomware operation in what researchers describe as the first observed instance of the state-sponsored actor using existing ransomware infrastructure.

A Months-Long Intrusion

Unit 42's incident response investigation spanned from May 28, 2024, to September 5, 2024. Initial access was achieved through a compromised user account in late May, after which the threat actors maintained persistent access for over three months before deploying Play ransomware.

Unit 42 stated they have "moderate confidence that Andariel, or a faction of the group, is now collaborating with the Play ransomware group."

Sliver, DTrack, and Credential Theft

Once inside the victim network, Andariel deployed the open-source Sliver C2 framework alongside their signature custom infostealer DTrack. Payloads were spread laterally via SMB connections using the net use command to access administrative shares (C$) across the network. Sliver beaconing activity remained consistent throughout the months-long intrusion.

Credential theft was extensive, leveraging Mimikatz, Task Manager LSASS dumps, and extraction of SAM and security registry hives. The attackers also created malicious services, established RDP sessions, and used Sliver's C2 capabilities to exfiltrate network configuration data.

The Ransomware Endgame

Leading up to the Play ransomware deployment on September 5, the attackers escalated significantly. They deployed a custom tool to abuse Windows Access Tokens, used PsExec for lateral movement and privilege escalation to SYSTEM, and systematically uninstalled EDR protection across multiple endpoints. Both Andariel and Play ransomware activity shared the same compromised account and staging directory — C:\Users\Public\Music.

Initial Access Broker or Full Affiliate?

The nature of the collaboration remains an open question. While Play ransomware has publicly stated it does not operate a Ransomware-as-a-Service (RaaS) model, the overlap suggests Andariel may have acted as an initial access broker (IAB) selling network access to Play operators — or may have become a full affiliate.

Unit 42 noted: "If Play ransomware does not provide a RaaS ecosystem as it claims, Jumpy Pisces might only have acted as an IAB."

This development represents a significant evolution in North Korean cyber operations. The collaboration between a state-sponsored espionage group and a criminal ransomware operation blurs the lines between geopolitical intelligence gathering and financially motivated cybercrime — a trend that defenders across all sectors should monitor closely.

Detection coverage

Read the full analysis on IntelFusions