A North Korean state-sponsored espionage group serving as the precursor to a financially motivated ransomware deployment — that is the alarming conclusion of an incident response engagement documented by Unit 42 in October 2024. The report provides the first confirmed public link between Andariel (tracked as Jumpy Pisces) and a Play ransomware attack — a group that had publicly denied having criminal affiliates.
Five Months of Undetected Access
Andariel gained initial access in late May 2024 via a compromised user account obtained through a perimeter firewall device. Over the following months, the group spread two tools laterally via SMB: the open-source Sliver C2 framework and DTrack, its custom RAT. EDR blocked DTrack execution, but Sliver beaconing — with intermittent check-ins and quiet periods in July — evaded detection for nearly four months.
The Handoff and Ransomware Deployment
In early September 2024, a second unidentified threat actor accessed the network through the same compromised account, immediately displaying ransomware-preparation behaviour: credential harvesting with Mimikatz, privilege escalation, and systematic EDR sensor uninstallation. Play ransomware was deployed the following day.
- Sliver: Open-source C2, Andariel phase (May–September 2024)
- DTrack: Custom RAT propagated via SMB, blocked by EDR
- Mimikatz: Credential dumping, pre-ransomware phase
- PsExec: Remote execution and lateral movement
"Network defenders should view Jumpy Pisces activity as a potential precursor to ransomware attacks, not just espionage, underscoring the need for heightened vigilance," Unit 42 researchers stated.
Defenders should treat Sliver C2 dwell activity or DTrack SMB propagation as urgent signals — not merely espionage indicators but potential ransomware precursors requiring immediate containment before a second-stage actor can capitalise on the access.