Threat reportAPTTL-2026-1766

Operation Double Barrel: State-Sponsored Threat Group Ties to Gunra Ransomware Exploit Korean Financial Security Software

criticalACTIVE

Operation Double Barrel (TL-2026-1766), also tracked as Operation Double Barrel, is a critical-severity advanced persistent threat campaign, first published 2026-07-30. It is linked to a North Korea-nexus actor with medium confidence, affects Unspecified (withheld by joint advisory pending vendor disclosure), maps to 35 MITRE ATT&CK techniques (T1003, T1021, T1027), and is covered by 9 detection rules and 34 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
0None referenced
Techniques
35MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
34Indicators of compromise

Key facts for TL-2026-1766

Threat ID
TL-2026-1766
Also known as
Operation Double Barrel
Severity
CRITICAL
Status
ACTIVE
Category
APT
First published
Last reviewed
Attribution confidence
MEDIUM
Nation-state nexus
North Korea
Motivation
ESPIONAGE
Target sectors
news - media, education, health, manufacturing, financial services
Target regions
south korea, East Asia
Detection rules
9
Indicators of compromise
34

Malware and tooling in Operation Double Barrel

Malware and tooling: Agamemnon Downloader, Bankshot, Gunra Ransomware, LPEClient, PostNapTea, ThreatNeedle - S0665, wAgentTea, Certipy / PetitPotam, FileZilla / WinSCP / Plink, Nircmd, PsExec / Impacket, Socat / OpenSSH

How Operation Double Barrel works

A joint advisory from South Korea's NIS, NPA, KISA, and FSI, detailed by AhnLab ASEC, documents a state-sponsored threat group that from 2025 through H1 2026 exploited vulnerabilities in Korean financial security software to deploy the Struggle (SIGNBT 3.0) and Brandoor (COPPERHEDGE) backdoors via watering-hole and spear-phishing attacks against Korean media, education, healthcare, and manufacturing organizations. ASEC found overlapping techniques, tools, and infrastructure between this state-sponsored actor and the Gunra ransomware group, suggesting a possible operational relationship.

On 2026-07-30, South Korea's National Intelligence Service (NIS), National Police Agency (NPA), Korea Internet & Security Agency (KISA), and Financial Security Institute (FSI) jointly published 'Operation Double Barrel,' a cybersecurity advisory with accompanying AhnLab ASEC technical analysis documenting a state-sponsored threat group's campaign against Korean critical sectors. From 2025 through the first half of 2026, the actor exploited unpatched vulnerabilities in two Korean financial security software products — referred to only as 'Financial Security Software A' and 'Financial Security Software I' pending vendor disclosure — to gain initial access via watering-hole and spear-phishing attacks. Multiple compromised distribution sites were traced back to a single Korean web-development/management company, indicating the watering holes were staged through a shared third-party supply-chain weakness rather than independently compromised per victim.

Post-exploitation, the actor deployed two backdoors named in the advisory: Struggle (also tracked as SIGNBT 3.0) and Brandoor (also tracked as COPPERHEDGE). Both malware family names — SIGNBT and COPPERHEDGE (aka Manuscrypt) — are independently and extensively documented across multiple prior campaigns (Kaspersky's 'A cascade of compromise' 3CX-adjacent reporting, CISA's HIDDEN COBRA malware analysis report MAR-10288834-1.v1, and the 2025 'Operation SyncHole' watering-hole campaign against South Korean software, IT, financial, semiconductor, and telecom firms) as tooling historically associated with the Lazarus Group / APT38 / HIDDEN COBRA / Stardust Chollima cluster. The Operation Double Barrel advisory itself withholds formal attribution to a named group, describing the actor only as 'state-sponsored'; the malware-family overlap with previously attributed Lazarus tooling supports a MEDIUM-confidence assessment of a DPRK nexus, not a confirmed one. SIGNBT communications use distinctive class-name/function-name C2 protocol prefixes (SIGNBTLG/SIGNBTKE/SIGNBTGC) with XOR/base64 and, in later variants, Curve25519 key exchange with ChaCha20 symmetric encryption; COPPERHEDGE stores its configuration in an NTFS alternate data stream and exposes roughly 30 C2 commands (0x2003-0x2032) with randomized HTTP parameter names for obfuscation. Precursor-campaign tooling in the same lineage (ThreatNeedle, wAgent, Agamemnon Downloader, LPEClient) used DLL side-loading (e.g., masquerading as PCAuditex.dll, spoolsv.exe/ualapi.dll hijacking), reflective/Tartarus-TpAllocInject loading, and RSA/AES key exchange.

For lateral movement and post-compromise operations inside victim networks, ASEC observed use of PsExec and Impacket (lateral movement/remote execution), Certipy and PetitPotam (Active Directory certificate-service abuse), TightVNC and a tool ASEC calls HookShot (interactive remote access), FileZilla, WinSCP, and Plink (data staging, exfiltration, and SSH tunneling), Socat and OpenSSH (reverse tunneling), UACMe (UAC-bypass privilege escalation), and Nircmd (silent command execution) — a toolkit largely composed of legitimate, dual-use administration software rather than bespoke offensive tooling, consistent with a defense-evasion strategy of blending into normal admin activity.

The advisory's most significant finding is the documented overlap between this state-sponsored actor and the Gunra ransomware group — a financially motivated, double-extortion ransomware operation (built on leaked Conti v2 source code, first observed publicly in April 2025) that encrypts files with a '.ENCRT' extension and drops a 'R3ADM3.txt' ransom note, negotiating via a Tor-hosted portal with a five-day payment deadline. ASEC identified identical vulnerability-exploitation patterns, matching SSH key fingerprints, shared C2 infrastructure (domains, IPs, and reverse-tunneling endpoints), and common anti-forensic techniques between the two clusters, suggesting either a shared-services relationship, tool/infrastructure leasing, or a degree of operational convergence between state-sponsored espionage activity and a nominally independent ransomware crew — a pattern consistent with prior CISA reporting (AA23-040a) on DPRK state actors using ransomware proceeds to help fund broader cyber operations.

Separately, ASEC's March 2026 Korean financial-sector threat report documents a related — and possibly overlapping — watering-hole campaign in which the 'AnySign4PC' financial security/browser-integration software was exploited for remote code execution, reused across multiple watering-hole distribution sites; no CVE identifier has been published for this flaw. The Operation Double Barrel advisory's own appendix (containing the campaign-specific IOC set: file hashes, domains, and IPs) was not accessible via public fetch at analysis time — the IOCs, malware-family details, and toolkit entries below are therefore drawn from the independently sourced malware-family and tooling literature (Operation SyncHole, CISA COPPERHEDGE MAR, Gunra ransomware research) that the advisory explicitly ties its Struggle/SIGNBT 3.0 and Brandoor/COPPERHEDGE naming to, and are documented as such rather than as confirmed Double-Barrel-specific artifacts.

MITRE ATT&CK techniques used in TL-2026-1766

Credential Access

T1003 OS Credential Dumping; T1649 Steal or Forge Authentication Certificates

Lateral Movement

T1021 Remote Services; T1570 Lateral Tool Transfer

Defense Evasion

T1027 Obfuscated Files or Information; T1055 Process Injection; T1140 Deobfuscate/Decode Files or Information; T1564 Hide Artifacts; T1620 Reflective Code Loading; T1622 Debugger Evasion

Exfiltration

T1041 Exfiltration Over C2 Channel; T1048 Exfiltration Over Alternative Protocol

Execution

T1047 Windows Management Instrumentation; T1059 Command and Scripting Interpreter; T1204 User Execution

Discovery

T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery

Command and Control

T1071 Application Layer Protocol; T1090 Proxy; T1105 Ingress Tool Transfer; T1573 Encrypted Channel

persistence

T1098 Account Manipulation

Initial Access

T1189 Drive-by Compromise; T1190 Exploit Public-Facing Application; T1195 Supply Chain Compromise; T1566 Phishing

stealth

T1218 System Binary Proxy Execution; T1574 Hijack Execution Flow

Impact

T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery

Persistence

T1547 Boot or Logon Autostart Execution

Privilege Escalation

T1548 Abuse Elevation Control Mechanism

Resource Development

T1583 Acquire Infrastructure; T1608 Stage Capabilities

Affected products and versions in Operation Double Barrel

  • Unspecified (withheld by joint advisory pending vendor disclosure) — Financial Security Software A
    Vulnerable versions: Unspecified - not publicly disclosed by NIS/NPA/KISA/FSI/ASEC as of 2026-07-30
    Fixed in: Unspecified
  • Unspecified (withheld by joint advisory pending vendor disclosure) — Financial Security Software I
    Vulnerable versions: Unspecified - not publicly disclosed by NIS/NPA/KISA/FSI/ASEC as of 2026-07-30
    Fixed in: Unspecified

Remediation for Operation Double Barrel

Patches

  • Apply vendor patches for 'Financial Security Software A' and 'Financial Security Software I' once the vendor(s) publicly disclose them — not yet named as of 2026-07-30.
  • Where financial security software includes AnySign4PC-class browser-security plug-ins, deploy the vendor's post-March-2026 patched build and block prior watering-hole distribution sites.

Immediate actions

  • Block/monitor known related C2 domains and URLs (smartmanagerex.com, thek-portal.com, builsf.com, www.rsdf.kr, www.shcpump.com, htns.com, kadsm.org) and any watering-hole sites traced to the same Korean web-development/management vendor referenced in the advisory.
  • Hunt for DLL side-loading/search-order hijacking (e.g. spoolsv.exe/ualapi.dll, files masquerading as PCAuditex.dll) and for NTFS alternate-data-stream configuration storage consistent with SIGNBT/COPPERHEDGE.
  • Audit SSH authorized_keys and known_hosts on externally-facing and jump/bastion hosts for unauthorized key reuse — the advisory cites matching SSH key fingerprints as a primary state-actor/Gunra overlap indicator.
  • Restrict and alert on use of PsExec, Impacket, Certipy, PetitPotam, TightVNC, Plink, Socat, and OpenSSH tunneling outside authorized administrative workflows.

Workarounds

  • Disable or restrict auto-loading of financial security software browser plug-ins on systems in targeted sectors until patch status is confirmed.
  • Enforce application allow-listing to block unauthorized execution of TightVNC, Socat, Plink, and similar dual-use tunneling/remote-access tools.

Longer-term hardening

  • Deploy EDR with behavioral detection tuned for DLL search-order hijacking, reflective code loading, process injection, and UAC-bypass techniques (UACMe).
  • Require vendor security review and code-signing verification for mandatory Korean financial security software plug-ins before browser integration is permitted.
  • Segment and closely monitor networks at media, education, healthcare, and manufacturing organizations that rely on mandated Korean financial security software.
  • Establish a supply-chain accountability review for the shared web-development/management provider linked to multiple compromised watering-hole sites.

Timeline of Operation Double Barrel

  • Earlier, related Lazarus watering-hole campaign (Operation SyncHole) deploys an updated ThreatNeedle loader (masquerading as PCAuditex.dll) against South Korean software/IT/financial targets; precursor tooling later evolved into the Struggle/SIGNBT 3.0 and Brandoor/COPPERHEDGE backdoors later named in Operation Double Barrel.
  • SIGNBT backdoor introduced and escalated within the precursor Operation SyncHole campaign, alongside wAgent and Agamemnon downloader deployments, per Kaspersky/Securelist analysis.
  • Per the joint NIS/NPA/KISA/FSI advisory, the state-sponsored actor's exploitation of Korean financial security software and deployment of Struggle/SIGNBT 3.0 and Brandoor/COPPERHEDGE begins (dated broadly to 2025).
  • Latest observed C2 beacon timestamp for the precursor Operation SyncHole infrastructure (wake timestamp 1739839071), indicating attacker activity concentrated in a GMT+9 operating window.
  • The Gunra ransomware group first emerges publicly, built on leaked Conti v2 source code, operating a double-extortion model via a Tor-hosted negotiation portal.
  • ASEC's March 2026 Korean financial-sector threat report documents the AnySign4PC financial security software vulnerability exploited for remote code execution, reused across multiple watering-hole distribution sites.
  • Campaign activity continues into H1 2026, with watering-hole and spear-phishing attacks against Korean media, education, healthcare, and manufacturing organizations, per the joint advisory's stated timeframe.
  • South Korea's NIS, NPA, KISA, and FSI jointly publish 'Operation Double Barrel'; AhnLab ASEC's accompanying technical analysis publicly documents overlapping techniques, tools, and infrastructure — including shared SSH key fingerprints and C2 infrastructure — between the state-sponsored actor and the Gunra ransomware group.

Sources cited for Operation Double Barrel

Detection coverage for TL-2026-1766

As of 2026-07-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1766 across Splunk SPL, Microsoft KQL and Sigma, covering 34 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
34 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats