Threat reportAPTTL-2026-1766
Operation Double Barrel: State-Sponsored Threat Group Ties to Gunra Ransomware Exploit Korean Financial Security Software
Operation Double Barrel (TL-2026-1766), also tracked as Operation Double Barrel, is a critical-severity advanced persistent threat campaign, first published 2026-07-30. It is linked to a North Korea-nexus actor with medium confidence, affects Unspecified (withheld by joint advisory pending vendor disclosure), maps to 35 MITRE ATT&CK techniques (T1003, T1021, T1027), and is covered by 9 detection rules and 34 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 0None referenced
- Techniques
- 35MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 34Indicators of compromise
Key facts for TL-2026-1766
- Threat ID
- TL-2026-1766
- Also known as
- Operation Double Barrel
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- APT
- First published
- Last reviewed
- Attribution confidence
- MEDIUM
- Nation-state nexus
- North Korea
- Motivation
- ESPIONAGE
- Target sectors
- news - media, education, health, manufacturing, financial services
- Target regions
- south korea, East Asia
- Detection rules
- 9
- Indicators of compromise
- 34
Malware and tooling in Operation Double Barrel
Malware and tooling: Agamemnon Downloader, Bankshot, Gunra Ransomware, LPEClient, PostNapTea, ThreatNeedle - S0665, wAgentTea, Certipy / PetitPotam, FileZilla / WinSCP / Plink, Nircmd, PsExec / Impacket, Socat / OpenSSH
How Operation Double Barrel works
A joint advisory from South Korea's NIS, NPA, KISA, and FSI, detailed by AhnLab ASEC, documents a state-sponsored threat group that from 2025 through H1 2026 exploited vulnerabilities in Korean financial security software to deploy the Struggle (SIGNBT 3.0) and Brandoor (COPPERHEDGE) backdoors via watering-hole and spear-phishing attacks against Korean media, education, healthcare, and manufacturing organizations. ASEC found overlapping techniques, tools, and infrastructure between this state-sponsored actor and the Gunra ransomware group, suggesting a possible operational relationship.
On 2026-07-30, South Korea's National Intelligence Service (NIS), National Police Agency (NPA), Korea Internet & Security Agency (KISA), and Financial Security Institute (FSI) jointly published 'Operation Double Barrel,' a cybersecurity advisory with accompanying AhnLab ASEC technical analysis documenting a state-sponsored threat group's campaign against Korean critical sectors. From 2025 through the first half of 2026, the actor exploited unpatched vulnerabilities in two Korean financial security software products — referred to only as 'Financial Security Software A' and 'Financial Security Software I' pending vendor disclosure — to gain initial access via watering-hole and spear-phishing attacks. Multiple compromised distribution sites were traced back to a single Korean web-development/management company, indicating the watering holes were staged through a shared third-party supply-chain weakness rather than independently compromised per victim.
Post-exploitation, the actor deployed two backdoors named in the advisory: Struggle (also tracked as SIGNBT 3.0) and Brandoor (also tracked as COPPERHEDGE). Both malware family names — SIGNBT and COPPERHEDGE (aka Manuscrypt) — are independently and extensively documented across multiple prior campaigns (Kaspersky's 'A cascade of compromise' 3CX-adjacent reporting, CISA's HIDDEN COBRA malware analysis report MAR-10288834-1.v1, and the 2025 'Operation SyncHole' watering-hole campaign against South Korean software, IT, financial, semiconductor, and telecom firms) as tooling historically associated with the Lazarus Group / APT38 / HIDDEN COBRA / Stardust Chollima cluster. The Operation Double Barrel advisory itself withholds formal attribution to a named group, describing the actor only as 'state-sponsored'; the malware-family overlap with previously attributed Lazarus tooling supports a MEDIUM-confidence assessment of a DPRK nexus, not a confirmed one. SIGNBT communications use distinctive class-name/function-name C2 protocol prefixes (SIGNBTLG/SIGNBTKE/SIGNBTGC) with XOR/base64 and, in later variants, Curve25519 key exchange with ChaCha20 symmetric encryption; COPPERHEDGE stores its configuration in an NTFS alternate data stream and exposes roughly 30 C2 commands (0x2003-0x2032) with randomized HTTP parameter names for obfuscation. Precursor-campaign tooling in the same lineage (ThreatNeedle, wAgent, Agamemnon Downloader, LPEClient) used DLL side-loading (e.g., masquerading as PCAuditex.dll, spoolsv.exe/ualapi.dll hijacking), reflective/Tartarus-TpAllocInject loading, and RSA/AES key exchange.
For lateral movement and post-compromise operations inside victim networks, ASEC observed use of PsExec and Impacket (lateral movement/remote execution), Certipy and PetitPotam (Active Directory certificate-service abuse), TightVNC and a tool ASEC calls HookShot (interactive remote access), FileZilla, WinSCP, and Plink (data staging, exfiltration, and SSH tunneling), Socat and OpenSSH (reverse tunneling), UACMe (UAC-bypass privilege escalation), and Nircmd (silent command execution) — a toolkit largely composed of legitimate, dual-use administration software rather than bespoke offensive tooling, consistent with a defense-evasion strategy of blending into normal admin activity.
The advisory's most significant finding is the documented overlap between this state-sponsored actor and the Gunra ransomware group — a financially motivated, double-extortion ransomware operation (built on leaked Conti v2 source code, first observed publicly in April 2025) that encrypts files with a '.ENCRT' extension and drops a 'R3ADM3.txt' ransom note, negotiating via a Tor-hosted portal with a five-day payment deadline. ASEC identified identical vulnerability-exploitation patterns, matching SSH key fingerprints, shared C2 infrastructure (domains, IPs, and reverse-tunneling endpoints), and common anti-forensic techniques between the two clusters, suggesting either a shared-services relationship, tool/infrastructure leasing, or a degree of operational convergence between state-sponsored espionage activity and a nominally independent ransomware crew — a pattern consistent with prior CISA reporting (AA23-040a) on DPRK state actors using ransomware proceeds to help fund broader cyber operations.
Separately, ASEC's March 2026 Korean financial-sector threat report documents a related — and possibly overlapping — watering-hole campaign in which the 'AnySign4PC' financial security/browser-integration software was exploited for remote code execution, reused across multiple watering-hole distribution sites; no CVE identifier has been published for this flaw. The Operation Double Barrel advisory's own appendix (containing the campaign-specific IOC set: file hashes, domains, and IPs) was not accessible via public fetch at analysis time — the IOCs, malware-family details, and toolkit entries below are therefore drawn from the independently sourced malware-family and tooling literature (Operation SyncHole, CISA COPPERHEDGE MAR, Gunra ransomware research) that the advisory explicitly ties its Struggle/SIGNBT 3.0 and Brandoor/COPPERHEDGE naming to, and are documented as such rather than as confirmed Double-Barrel-specific artifacts.
MITRE ATT&CK techniques used in TL-2026-1766
Credential Access
T1003 OS Credential Dumping; T1649 Steal or Forge Authentication Certificates
Lateral Movement
T1021 Remote Services; T1570 Lateral Tool Transfer
Defense Evasion
T1027 Obfuscated Files or Information; T1055 Process Injection; T1140 Deobfuscate/Decode Files or Information; T1564 Hide Artifacts; T1620 Reflective Code Loading; T1622 Debugger Evasion
Exfiltration
T1041 Exfiltration Over C2 Channel; T1048 Exfiltration Over Alternative Protocol
Execution
T1047 Windows Management Instrumentation; T1059 Command and Scripting Interpreter; T1204 User Execution
Discovery
T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery
Command and Control
T1071 Application Layer Protocol; T1090 Proxy; T1105 Ingress Tool Transfer; T1573 Encrypted Channel
persistence
Initial Access
T1189 Drive-by Compromise; T1190 Exploit Public-Facing Application; T1195 Supply Chain Compromise; T1566 Phishing
stealth
T1218 System Binary Proxy Execution; T1574 Hijack Execution Flow
Impact
T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery
Persistence
T1547 Boot or Logon Autostart Execution
Privilege Escalation
T1548 Abuse Elevation Control Mechanism
Resource Development
Affected products and versions in Operation Double Barrel
- Unspecified (withheld by joint advisory pending vendor disclosure) — Financial Security Software A
Vulnerable versions: Unspecified - not publicly disclosed by NIS/NPA/KISA/FSI/ASEC as of 2026-07-30
Fixed in: Unspecified - Unspecified (withheld by joint advisory pending vendor disclosure) — Financial Security Software I
Vulnerable versions: Unspecified - not publicly disclosed by NIS/NPA/KISA/FSI/ASEC as of 2026-07-30
Fixed in: Unspecified
Remediation for Operation Double Barrel
Patches
- Apply vendor patches for 'Financial Security Software A' and 'Financial Security Software I' once the vendor(s) publicly disclose them — not yet named as of 2026-07-30.
- Where financial security software includes AnySign4PC-class browser-security plug-ins, deploy the vendor's post-March-2026 patched build and block prior watering-hole distribution sites.
Immediate actions
- Block/monitor known related C2 domains and URLs (smartmanagerex.com, thek-portal.com, builsf.com, www.rsdf.kr, www.shcpump.com, htns.com, kadsm.org) and any watering-hole sites traced to the same Korean web-development/management vendor referenced in the advisory.
- Hunt for DLL side-loading/search-order hijacking (e.g. spoolsv.exe/ualapi.dll, files masquerading as PCAuditex.dll) and for NTFS alternate-data-stream configuration storage consistent with SIGNBT/COPPERHEDGE.
- Audit SSH authorized_keys and known_hosts on externally-facing and jump/bastion hosts for unauthorized key reuse — the advisory cites matching SSH key fingerprints as a primary state-actor/Gunra overlap indicator.
- Restrict and alert on use of PsExec, Impacket, Certipy, PetitPotam, TightVNC, Plink, Socat, and OpenSSH tunneling outside authorized administrative workflows.
Workarounds
- Disable or restrict auto-loading of financial security software browser plug-ins on systems in targeted sectors until patch status is confirmed.
- Enforce application allow-listing to block unauthorized execution of TightVNC, Socat, Plink, and similar dual-use tunneling/remote-access tools.
Longer-term hardening
- Deploy EDR with behavioral detection tuned for DLL search-order hijacking, reflective code loading, process injection, and UAC-bypass techniques (UACMe).
- Require vendor security review and code-signing verification for mandatory Korean financial security software plug-ins before browser integration is permitted.
- Segment and closely monitor networks at media, education, healthcare, and manufacturing organizations that rely on mandated Korean financial security software.
- Establish a supply-chain accountability review for the shared web-development/management provider linked to multiple compromised watering-hole sites.
Timeline of Operation Double Barrel
- Earlier, related Lazarus watering-hole campaign (Operation SyncHole) deploys an updated ThreatNeedle loader (masquerading as PCAuditex.dll) against South Korean software/IT/financial targets; precursor tooling later evolved into the Struggle/SIGNBT 3.0 and Brandoor/COPPERHEDGE backdoors later named in Operation Double Barrel.
- SIGNBT backdoor introduced and escalated within the precursor Operation SyncHole campaign, alongside wAgent and Agamemnon downloader deployments, per Kaspersky/Securelist analysis.
- Per the joint NIS/NPA/KISA/FSI advisory, the state-sponsored actor's exploitation of Korean financial security software and deployment of Struggle/SIGNBT 3.0 and Brandoor/COPPERHEDGE begins (dated broadly to 2025).
- Latest observed C2 beacon timestamp for the precursor Operation SyncHole infrastructure (wake timestamp 1739839071), indicating attacker activity concentrated in a GMT+9 operating window.
- The Gunra ransomware group first emerges publicly, built on leaked Conti v2 source code, operating a double-extortion model via a Tor-hosted negotiation portal.
- ASEC's March 2026 Korean financial-sector threat report documents the AnySign4PC financial security software vulnerability exploited for remote code execution, reused across multiple watering-hole distribution sites.
- Campaign activity continues into H1 2026, with watering-hole and spear-phishing attacks against Korean media, education, healthcare, and manufacturing organizations, per the joint advisory's stated timeframe.
- South Korea's NIS, NPA, KISA, and FSI jointly publish 'Operation Double Barrel'; AhnLab ASEC's accompanying technical analysis publicly documents overlapping techniques, tools, and infrastructure — including shared SSH key fingerprints and C2 infrastructure — between the state-sponsored actor and the Gunra ransomware group.
Sources cited for Operation Double Barrel
- [Joint Cybersecurity Advisory] Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware Group)
- A cascade of compromise: unveiling Lazarus' new campaign
- Operation SyncHole: Lazarus APT updates its toolset in watering hole attacks
- March 2026 Security Issues in the Korean & Global Financial Sector
- MAR-10288834-1.v1 – North Korean Remote Access Tool: COPPERHEDGE
- Gunra Ransomware – A Brief Analysis
- N. Korean Lazarus Group Targets Software Vendor Using Known Flaws
- Lazarus hackers breached dev repeatedly to deploy SIGNBT malware
- South Korean Companies Targeted by Lazarus via Watering Hole Attacks, Zero-Days
- Kaspersky uncovers new Lazarus-led cyberattacks targeting South Korean supply chains
- Gunra ransomware group profile
- CISA issues alert with South Korean government about DPRK's ransomware antics
- #StopRansomware: Ransomware Attacks on Critical Infrastructure Fund DPRK Malicious Cyber Activities
Detection coverage for TL-2026-1766
As of 2026-07-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1766 across Splunk SPL, Microsoft KQL and Sigma, covering 34 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.