Recent research indicates that cyberattack tools and infrastructure from North Korea’s Lazarus Group have been shared with ransomware criminals targeting South Korean organizations. This finding comes from a technical report by cybersecurity firm AhnLab, released alongside a joint advisory from four South Korean security and intelligence agencies. The implications of this collaboration are significant for defenders, as it highlights a growing entanglement between state-sponsored actors and ransomware operations.
Parallel Campaigns Against South Korea
AhnLab’s report details how the Lazarus Group and the Gunra ransomware scheme conducted parallel campaigns against South Korean targets from 2025 through the first half of 2026. While Lazarus focused on espionage, installing backdoors in at least 72 organizations—including government agencies and cryptocurrency exchanges—Gunra utilized its access to encrypt files, steal data, and demand ransom payments.
Shared Techniques and Infrastructure
Both groups exploited the same vulnerabilities in Korean financial security software, which is essential for users of banking and government services. They employed identical malware filenames, execution arguments, privilege escalation tools, command-and-control servers, and even the same SSH key fingerprint. AhnLab has named this campaign “Operation Double Barrel,” noting a “high likelihood of technical linkage” between the two groups, although it refrained from definitively attributing the campaigns to the same actor.
Watering-Hole Attacks and Spearphishing
The attackers compromised 15 legitimate Korean websites across various industries, using them for watering-hole attacks that redirected visitors to malicious infrastructure. Additionally, they conducted spearphishing campaigns, including one targeting a Korean defense company with emails disguised as surveys about GaN semiconductors. AhnLab observed that some lure pages appeared to be generated using AI.
Growing Threat Landscape
The findings contribute to a broader understanding of how North Korean hackers are increasingly integrating into the ransomware ecosystem. In the past 18 months, various North Korean state-sponsored actors have been linked to multiple ransomware operations. The Gunra group, which emerged in April 2025, initially targeted five South Korean companies and has since transitioned to a ransomware-as-a-service model.
AhnLab warns that the vulnerabilities being exploited extend beyond targeted organizations, affecting personal PCs and enterprise environments alike. Users may be at risk simply by visiting compromised legitimate websites, particularly if they have outdated security software.
For further details, refer to the full report by AhnLab.


