North Korea’s Lazarus Group shares cyberattack tools with ransomware gang targeting South Korea, agencies warn

Published:

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Recent research indicates that cyberattack tools and infrastructure from North Korea’s Lazarus Group have been shared with ransomware criminals targeting South Korean organizations. This finding comes from a technical report by cybersecurity firm AhnLab, released alongside a joint advisory from four South Korean security and intelligence agencies. The implications of this collaboration are significant for defenders, as it highlights a growing entanglement between state-sponsored actors and ransomware operations.

Parallel Campaigns Against South Korea

AhnLab’s report details how the Lazarus Group and the Gunra ransomware scheme conducted parallel campaigns against South Korean targets from 2025 through the first half of 2026. While Lazarus focused on espionage, installing backdoors in at least 72 organizations—including government agencies and cryptocurrency exchanges—Gunra utilized its access to encrypt files, steal data, and demand ransom payments.

Shared Techniques and Infrastructure

Both groups exploited the same vulnerabilities in Korean financial security software, which is essential for users of banking and government services. They employed identical malware filenames, execution arguments, privilege escalation tools, command-and-control servers, and even the same SSH key fingerprint. AhnLab has named this campaign “Operation Double Barrel,” noting a “high likelihood of technical linkage” between the two groups, although it refrained from definitively attributing the campaigns to the same actor.

Watering-Hole Attacks and Spearphishing

The attackers compromised 15 legitimate Korean websites across various industries, using them for watering-hole attacks that redirected visitors to malicious infrastructure. Additionally, they conducted spearphishing campaigns, including one targeting a Korean defense company with emails disguised as surveys about GaN semiconductors. AhnLab observed that some lure pages appeared to be generated using AI.

Growing Threat Landscape

The findings contribute to a broader understanding of how North Korean hackers are increasingly integrating into the ransomware ecosystem. In the past 18 months, various North Korean state-sponsored actors have been linked to multiple ransomware operations. The Gunra group, which emerged in April 2025, initially targeted five South Korean companies and has since transitioned to a ransomware-as-a-service model.

AhnLab warns that the vulnerabilities being exploited extend beyond targeted organizations, affecting personal PCs and enterprise environments alike. Users may be at risk simply by visiting compromised legitimate websites, particularly if they have outdated security software.

For further details, refer to the full report by AhnLab.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Malicious Content Discovered on ‘third-party.com’ Domain Used in Over 1,700 Repositories

The domain "third-party.com," typically used as a documentation placeholder, has been identified as serving a ClickFix lure targeting Windows users while presenting a benign...

New MacSync Version Targets Crypto Enthusiasts with Advanced Infection Techniques

The emergence of the MacSync malware family marks a significant evolution in the landscape of cyber threats targeting macOS users, particularly those involved in...

Astrana Health Reports Data Breach Following Social Engineering Attack on Employees

Astrana Health has reported a data breach involving the theft of private and confidential information from its servers, following a social engineering attack that...

CloudSEK Addresses Escalating AI-Driven Cyber Risks in the Middle East

CloudSEK Tackles Rising AI-Driven Cyber Risks in the Middle East Cyber threats in the Middle East are escalating, with state-sponsored groups, ideologically motivated actors, and...