North Korean State Hackers May Be Sharing Tools With a Ransomware Gang Hitting South Korea

Published
Written by:
Lore Apostol
Lore Apostol
Cybersecurity Writer
Key Takeaways
  • Tool sharing: A state-sponsored threat actor tied to North Korea appears to have shared cyberattack tools and infrastructure with the Gunra ransomware group.
  • Shared indicators: AhnLab found identical malware filenames, C2 servers, and SSH key fingerprints linking the two campaigns.
  • Victim count: The state-sponsored actor compromised at least 72 organizations in 2026, while Gunra claimed 32 global victims as of March 2026.

A North Korea-linked state-sponsored threat group's cyberattack tools and infrastructure appear to have been shared with ransomware criminals targeting South Korean organizations. The connection was supported by research released Thursday alongside a joint advisory from four South Korean security and intelligence agencies: the National Intelligence Service, National Police Agency, KISA, and FSI.

AhnLab Details Operation Double Barrel

The North Korea state-sponsored campaign and the Gunra ransomware scheme ran parallel operations against South Korean targets from 2025 through the first half of this year, differing only in their final objective, cybersecurity firm AhnLab said. Both exploited the same vulnerabilities in Korean financial security software that is effectively mandatory for banking and government services. 

The state-sponsored actor installed espionage backdoors in at least 72 organizations in 2026, including government agencies, cryptocurrency exchanges, and IT service providers, while Gunra encrypted files, stole data, and demanded extortion payments. 

Industry breakdown of victim organizations identified in 2026 | Source: AhnLab
Industry breakdown of victim organizations identified in 2026 | Source: AhnLab

"The Korean financial security software currently being abused… is used not only in various enterprise environments but also on many personal PCs," warned the report (PDF).

Matching Malware and Infrastructure

AhnLab found both campaigns used identical malware filenames and execution arguments, the same privilege escalation tools, the same command-and-control (C2) servers, and the same SSH key fingerprint. 

Both even deleted their malware identically, renaming files to random four-character strings before wiping them.

Operation Double Barrel Attribution

AhnLab named the campaign "Operation Double Barrel" but stopped short of definitively attributing both operations to the same actor, saying the overlaps could reflect collaboration, shared infrastructure, or a common access broker. 

Watering hole attack flow | Source: AhnLab
Watering hole attack flow | Source: AhnLab

Attackers compromised 15 legitimate Korean websites, spanning media, education, healthcare, and manufacturing, for use in watering-hole attacks.

Gunra's Origins and Broader Context

Gunra emerged in April 2025, initially targeting five South Korean companies, and built its ransomware on leaked Conti v2 source code before shifting to a ransomware-as-a-service (RaaS) model in January. 

AhnLab separately attributed a related March 2026 watering-hole attack exploiting the same software to Lazarus Group in an earlier report published in April. Yet, the current joint advisory and Double Barrel report themselves stop short of naming Lazarus directly, referring only to "a state-sponsored threat group."

This month, South Korea confirmed a diplomatic academy cyberattack. In May, Kimsuky APT targeted South Korean entities to distribute backdoors, while April reports said that DPRK phishing campaigns targeted organizations in South Korea. In March, the South Korean tax office leaked cryptocurrency assets, leading to a wallet breach.


For a better user experience we recommend using a more modern browser. We support the latest version of the following browsers: For a better user experience we recommend using the latest version of the following browsers: