Cyberattack tools and infrastructure used by North Korea’s Lazarus Group appear to have been shared with ransomware criminals targeting South Korean organizations, according to new research released Thursday alongside a joint advisory by four South Korean security and intelligence agencies.
The technical report from cybersecurity firm AhnLab details how the state-sponsored North Korean group, widely tracked as Lazarus, and the Gunra ransomware scheme ran parallel campaigns against South Korean targets from 2025 through the first half of this year, differing only in their final objective.
Both groups exploited the same vulnerabilities in Korean financial security software products that are effectively mandatory for anyone using Korean banking or government services. Where the Lazarus hackers have installed espionage backdoors in at least 72 organizations in 2026 alone — including government agencies, cryptocurrency exchanges, and IT service providers — Gunra has instead used its access to encrypt files, steal data and demand an extortion payment.
According to AhnLab, both groups also used identical malware filenames and execution arguments, the same privilege escalation tools, the same command-and-control servers, and the same SSH key fingerprint — a cryptographic identifier that functions like a unique digital signature. Both even deleted their malware the same way, renaming files to random four-character strings before wiping them.
AhnLab named the campaign “Operation Double Barrel,” but stopped short of definitively attributing both campaigns to the same actor, saying the overlaps could indicate collaboration, shared infrastructure, or access brokering. It classified the cases as having “a high likelihood of technical linkage” requiring continued investigation.
As part of their campaign, the attackers compromised 15 legitimate Korean websites across multiple industries and used them for watering-hole attacks, redirecting selected visitors of those compromised sites to specific infrastructure that triggered the software flaws and injected malicious code into legitimate Microsoft processes.
The intelligence agencies’ advisory warns both individuals and organizations to take defensive measures against the threat. In particular, the advisory alerts users that they may be infected simply by visiting a legitimate website that has been compromised, especially if they have outdated security software installed.
The attackers also ran spearphishing campaigns, with one targeting a Korean defense company with emails disguised as a survey about GaN semiconductors. AhnLab noted that the attackers appeared to have used AI to generate some of their lure pages.
The report identified multiple websites used for watering-hole attacks managed by the same Korean website development company. AhnLab assessed that the attackers likely compromised the hosting provider first and then expanded access to client sites through the development company’s management system, rather than hacking each one individually.
The findings add to a growing body of evidence that Pyongyang-backed hackers are deepening their entanglement with the ransomware ecosystem. In the past 18 months, different North Korean state-sponsored actors have been linked to the Play, Qilin, and Medusa ransomware operations by researchers at Palo Alto Networks, Microsoft, and Symantec respectively.
The increasing adoption of third-party ransomware by North Korean actors came under focus back in 2024, when the U.S. Department of Justice unsealed an indictment against Rim Jong Hyok, an alleged member of the government’s Andariel Unit, for his alleged role in ransomware attacks on U.S. hospitals and healthcare companies.
The Gunra connection may represent something different. In those earlier cases, North Korean operators joined established criminal franchises as affiliates. Here, the evidence suggests the relationship may run the other direction — with state hackers supplying tools, exploits, and access to a smaller, newer group.
Gunra emerged in April 2025, initially targeting five South Korean companies. The group built its ransomware on leaked Conti v2 source code before transitioning to a ransomware-as-a-service model in January of this year. Prior to the AhnLab report, industry researchers had tentatively linked Gunra to Eastern European operators based on its Conti heritage.
As of March 2026, the group had claimed at least 32 victims globally across healthcare, manufacturing, IT, and other sectors. As with many RaaS schemes, it operates a double-extortion model, stealing data before encrypting systems and threatening to publish it on a Tor-based leak site.
AhnLab warned that the risk extends beyond the organizations specifically targeted.
“The Korean financial security software currently being abused… is used not only in various enterprise environments but also on many personal PCs,” the company said.
“Because the vulnerabilities can be triggered simply when a user accesses a specific page, not only explicitly targeted organizations but also general user environments running vulnerable software may be exposed to risk.”
