North Korea’s Lazarus Group shares cyberattack tools with ransomware gang targeting South Korea, agencies warn

Published:

spot_img

Recent research indicates that cyberattack tools and infrastructure from North Korea’s Lazarus Group have been shared with ransomware criminals targeting South Korean organizations. This finding comes from a technical report by cybersecurity firm AhnLab, released alongside a joint advisory from four South Korean security and intelligence agencies. The implications of this collaboration are significant for defenders, as it highlights a growing entanglement between state-sponsored actors and ransomware operations.

Parallel Campaigns Against South Korea

AhnLab’s report details how the Lazarus Group and the Gunra ransomware scheme conducted parallel campaigns against South Korean targets from 2025 through the first half of 2026. While Lazarus focused on espionage, installing backdoors in at least 72 organizations—including government agencies and cryptocurrency exchanges—Gunra utilized its access to encrypt files, steal data, and demand ransom payments.

Shared Techniques and Infrastructure

Both groups exploited the same vulnerabilities in Korean financial security software, which is essential for users of banking and government services. They employed identical malware filenames, execution arguments, privilege escalation tools, command-and-control servers, and even the same SSH key fingerprint. AhnLab has named this campaign “Operation Double Barrel,” noting a “high likelihood of technical linkage” between the two groups, although it refrained from definitively attributing the campaigns to the same actor.

Watering-Hole Attacks and Spearphishing

The attackers compromised 15 legitimate Korean websites across various industries, using them for watering-hole attacks that redirected visitors to malicious infrastructure. Additionally, they conducted spearphishing campaigns, including one targeting a Korean defense company with emails disguised as surveys about GaN semiconductors. AhnLab observed that some lure pages appeared to be generated using AI.

Growing Threat Landscape

The findings contribute to a broader understanding of how North Korean hackers are increasingly integrating into the ransomware ecosystem. In the past 18 months, various North Korean state-sponsored actors have been linked to multiple ransomware operations. The Gunra group, which emerged in April 2025, initially targeted five South Korean companies and has since transitioned to a ransomware-as-a-service model.

AhnLab warns that the vulnerabilities being exploited extend beyond targeted organizations, affecting personal PCs and enterprise environments alike. Users may be at risk simply by visiting compromised legitimate websites, particularly if they have outdated security software.

For further details, refer to the full report by AhnLab.

spot_img

Related articles

Recent articles

H96 Streaming Devices Linked to Ad Fraud Network, Spoofing Mobile Phones to Defraud Merchants

Recent findings have revealed that H96 streaming devices are linked to an extensive ad fraud network, which not only exploits users' internet connections but...

Coordinated Cyberattack Disrupts Operational Technology in 30+ Minnesota Water Utilities, Revealing Vulnerabilities and Response Gaps

In a significant cybersecurity incident, over 30 water and wastewater utilities in Minnesota were targeted by a coordinated cyberattack between July 26 and July...

Origin Energy Data Breach 2026: Unauthorized Access Exposes PII of 900,000 Customers

On July 28, 2026, Origin Energy confirmed a significant data breach impacting approximately 900,000 current and former customers. This incident involved unauthorized access and...

Mirage Kitten Unveils NightLedger Backdoor and WebSocket Tunnelers for Cyber-Espionage in Middle East and Africa

Recent research has unveiled a new set of malware tools attributed to the advanced persistent threat (APT) group known as Mirage Kitten, which is...