North Korea’s Lazarus Group shares cyberattack tools with ransomware gang targeting South Korea, agencies warn

Published:

spot_img

Recent research indicates that cyberattack tools and infrastructure from North Korea’s Lazarus Group have been shared with ransomware criminals targeting South Korean organizations. This finding comes from a technical report by cybersecurity firm AhnLab, released alongside a joint advisory from four South Korean security and intelligence agencies. The implications of this collaboration are significant for defenders, as it highlights a growing entanglement between state-sponsored actors and ransomware operations.

Parallel Campaigns Against South Korea

AhnLab’s report details how the Lazarus Group and the Gunra ransomware scheme conducted parallel campaigns against South Korean targets from 2025 through the first half of 2026. While Lazarus focused on espionage, installing backdoors in at least 72 organizations—including government agencies and cryptocurrency exchanges—Gunra utilized its access to encrypt files, steal data, and demand ransom payments.

Shared Techniques and Infrastructure

Both groups exploited the same vulnerabilities in Korean financial security software, which is essential for users of banking and government services. They employed identical malware filenames, execution arguments, privilege escalation tools, command-and-control servers, and even the same SSH key fingerprint. AhnLab has named this campaign “Operation Double Barrel,” noting a “high likelihood of technical linkage” between the two groups, although it refrained from definitively attributing the campaigns to the same actor.

Watering-Hole Attacks and Spearphishing

The attackers compromised 15 legitimate Korean websites across various industries, using them for watering-hole attacks that redirected visitors to malicious infrastructure. Additionally, they conducted spearphishing campaigns, including one targeting a Korean defense company with emails disguised as surveys about GaN semiconductors. AhnLab observed that some lure pages appeared to be generated using AI.

Growing Threat Landscape

The findings contribute to a broader understanding of how North Korean hackers are increasingly integrating into the ransomware ecosystem. In the past 18 months, various North Korean state-sponsored actors have been linked to multiple ransomware operations. The Gunra group, which emerged in April 2025, initially targeted five South Korean companies and has since transitioned to a ransomware-as-a-service model.

AhnLab warns that the vulnerabilities being exploited extend beyond targeted organizations, affecting personal PCs and enterprise environments alike. Users may be at risk simply by visiting compromised legitimate websites, particularly if they have outdated security software.

For further details, refer to the full report by AhnLab.

spot_img

Related articles

Recent articles

Atlassian Rovo Vulnerability Allows Data Exfiltration from Jira and Confluence

Recent findings have revealed a vulnerability in Atlassian's Rovo assistant that allows attacker-controlled instructions to extract data from Jira and Confluence. This issue was...

Qilin Ransomware Claim: Stade Français Investigates Data Leak After Cyberattack

Qilin Ransomware Claim: Stade Français Paris has confirmed it was targeted by a cyberattack that disrupted its information systems. The club reported that it...

Georgia Investigates Alleged Foreign Disinformation Campaign Targeting Russian Tourists

Georgia Investigates Alleged Foreign Disinformation Campaign Targeting Russian Tourists. The State Security Service of Georgia has initiated a criminal investigation into a purported disinformation...

Untrusted Data Safety

Microsoft Defender’s attack disruption now includes device isolation, a new response action that enhances protection for compromised endpoints. This capability was recently highlighted in...