Jumpy Pisces
2024-06-28 • Paloalto Networks • Threat Actor Groups Tracked by Palo Alto Networks…
Palo Alto Networks Unit 42 tracks Jumpy Pisces as a North Korean state-sponsored threat actor operating under the Reconnaissance General Bureau, also publicly known as Andariel, Hidden Cobra, and Onyx Sleet, and assessed to be a subgroup of the broader Lazarus Group that branched out around 2013. The group has historically conducted cyberespionage and financial crime, including development of the custom Maui ransomware for which a member was indicted by the U.S. Department of Justice, primarily targeting South Korean aerospace and defense, financial-services, and utilities and energy organizations through spear phishing, watering-hole attacks, and supply-chain compromise. In an incident identified in 2024, Unit 42 assessed with high confidence that Jumpy Pisces gained initial access to a victim network via a compromised account and used the Sliver framework and its custom DTrack malware for lateral movement, and assessed with moderate confidence that the same access was subsequently leveraged, with some cooperation from Jumpy Pisces, to deploy Play ransomware, marking the group's first observed collaboration with an established ransomware operation.
-
19
Related Actors
-
4
Related Reports
Related Actors
Related Reports
Top Authors
View all reports in this cluster