Operation Double Barrel: State-Sponsored Threat Group Ties to Gunra Ransomware Exploit Korean Financial Security Software — Threadlinqs Intelligence
As of 2026-07-30, Operation Double Barrel: State-Sponsored Threat Group Ties to Gunra Ransomware Exploit Korean Financial Security Software is a critical-severity apt threat attributed to Unnamed State-Sponsored Threat Group (assessed Lazarus Group (North Korea (Democratic People's Republic of Korea) - assessed, not confirmed in source advisory), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 34 indicators of compromise.
Threat ID: TL-2026-1766 · Severity: CRITICAL · Status: ACTIVE · Category: APT
Attribution: Unnamed State-Sponsored Threat Group (assessed Lazarus Group · North Korea (Democratic People's Republic of Korea) - assessed, not confirmed in source advisory · ESPIONAGE
A joint advisory from South Korea's NIS, NPA, KISA, and FSI, detailed by AhnLab ASEC, documents a state-sponsored threat group that from 2025 through H1 2026 exploited vulnerabilities in Korean
On 2026-07-30, South Korea's National Intelligence Service (NIS), National Police Agency (NPA), Korea Internet & Security Agency (KISA), and Financial Security Institute (FSI) jointly published 'Operation Double Barrel,' a cybersecurity advisory with accompanying AhnLab ASEC technical analysis documenting a state-sponsored threat group's campaign against Korean critical sectors. From 2025 through the first half of 2026, the actor exploited unpatched vulnerabilities in two Korean financial security software products — referred to only as 'Financial Security Software A' and 'Financial Security Software I' pending vendor disclosure — to gain initial access via watering-hole and spear-phishing attacks. Multiple compromised distribution sites were traced back to a single Korean web-development/management company, indicating the watering holes were staged through a shared third-party supply-chain weakness rather than independently compromised per victim.
Post-exploitation, the actor deployed two backdoors named in the advisory: Struggle (also tracked as SIGNBT 3.0) and Brandoor (also tracked as COPPERHEDGE). Both malware family names — SIGNBT and COPPERHEDGE (aka Manuscrypt) — are independently and extensively documented across multiple prior campaigns (Kaspersky's 'A cascade of compromise' 3CX-adjacent reporting, CISA's HIDDEN COBRA malware analysis report MAR-10288834-1.v1, and the 2025 'Operation SyncHole' watering-hole campaign against South Korean software, IT, financial, semiconductor, and telecom firms) as tooling historically associated with the Lazarus Group / APT38 / HIDDEN COBRA / Stardust Chollima cluster. The Operation Double Barrel advisory itself withholds formal attribution to a named group, describing the actor only as 'state-sponsored'; the malware-family overlap with previously attributed Lazarus tooling supports a MEDIUM-confidence assessment of a DPRK nexus, not a confirmed one. SIGNBT communications use distinctive class-name/function-name C2 protocol prefixes (SIGNBTLG/SIGNBTKE/SIGNBTGC) with XOR/base64 and, in later variants, Curve25519 key exchange with ChaCha20 symmetric encryption; COPPERHEDGE stores its configuration in an NTFS alternate data stream and exposes roughly 30 C2 commands (0x2003-0x2032) with randomized HTTP parameter names for obfuscation. Precursor-campaign tooling in the same lineage (ThreatNeedle, wAgent, Agamemnon Downloader, LPEClient) used DLL side-loading (e.g., masquerading as PCAuditex.dll, spoolsv.exe/ualapi.dll hijacking), reflective/Tartarus-TpAllocInject loading, and RSA/AES key exchange.
For lateral movement and post-compromise operations inside victim networks, ASEC observed use of PsExec and Impacket (lateral movement/remote execution), Certipy and PetitPotam (Active Directory certificate-service abuse), TightVNC and a tool ASEC calls HookShot (interactive remote access), FileZilla, WinSCP, and Plink (data staging, exfiltration, and SSH tunneling), Socat and OpenSSH (reverse tunneling), UACMe (UAC-bypass privilege escalation), and Nircmd (silent command execution) — a toolkit largely composed of legitimate, dual-use administration software rather than bespoke offensive tooling, consistent with a defense-evasion strategy of blending into normal admin activity.
The advisory's most significant finding is the documented overlap between this state-sponsored actor and the Gunra ransomware group — a financially motivated, double-extortion ransomware operation (built on leaked Conti v2 source code, first observed publicly in April 2025) that encrypts files with a '.ENCRT' extension and drops a 'R3ADM3.txt' ransom note, negotiating via a Tor-hosted portal with a five-day payment deadline. ASEC identified identical vulnerability-exploitation patterns, matching SSH key fingerprints, shared C2 infrastructure (domains, IPs, and reverse-tunneling endpoints), and common anti-forensic techniques between the two clusters, suggesting either a shared-services relationship, tool/infrastructure
Target sectors: news - media, education, health, manufacturing, financial services
Target regions: south korea, East Asia
Detections & IOCs
As of 2026-08-24, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 34 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, CRITICAL, threat intelligence, cybersecurity, T1583, T1608, T1189, T1566, T1190, T1195, T1204, T1218, T1059, T1047