# Operation Double Barrel: State-Sponsored Threat Group Ties to Gunra Ransomware Exploit Korean Financial Security Software

> A joint advisory from South Korea's NIS, NPA, KISA, and FSI, detailed by AhnLab ASEC, documents a state-sponsored threat group that from 2025 through H1 2026 exploited vulnerabilities in Korean financial security software to deploy the Struggle (SIGNBT 3.0) and Brandoor (COPPERHEDGE) backdoors via watering-hole and spear-phishing attacks against Korean media, education, healthcare, and manufacturing organizations. ASEC found overlapping techniques, tools, and infrastructure between this state-sponsored actor and the Gunra ransomware group, suggesting a possible operational relationship.

- **Published:** 2026-07-30T00:00:00Z
- **Last reviewed:** 2026-07-30T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1766
- **ID:** TL-2026-1766
- **Severity:** CRITICAL
- **Category:** APT
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 34 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On 2026-07-30, South Korea's National Intelligence Service (NIS), National Police Agency (NPA), Korea Internet & Security Agency (KISA), and Financial Security Institute (FSI) jointly published 'Operation Double Barrel,' a cybersecurity advisory with accompanying AhnLab ASEC technical analysis documenting a state-sponsored threat group's campaign against Korean critical sectors. From 2025 through the first half of 2026, the actor exploited unpatched vulnerabilities in two Korean financial security software products — referred to only as 'Financial Security Software A' and 'Financial Security Software I' pending vendor disclosure — to gain initial access via watering-hole and spear-phishing attacks. Multiple compromised distribution sites were traced back to a single Korean web-development/management company, indicating the watering holes were staged through a shared third-party supply-chain weakness rather than independently compromised per victim.

Post-exploitation, the actor deployed two backdoors named in the advisory: Struggle (also tracked as SIGNBT 3.0) and Brandoor (also tracked as COPPERHEDGE). Both malware family names — SIGNBT and COPPERHEDGE (aka Manuscrypt) — are independently and extensively documented across multiple prior campaigns (Kaspersky's 'A cascade of compromise' 3CX-adjacent reporting, CISA's HIDDEN COBRA malware analysis report MAR-10288834-1.v1, and the 2025 'Operation SyncHole' watering-hole campaign against South Korean software, IT, financial, semiconductor, and telecom firms) as tooling historically associated with the Lazarus Group / APT38 / HIDDEN COBRA / Stardust Chollima cluster. The Operation Double Barrel advisory itself withholds formal attribution to a named group, describing the actor only as 'state-sponsored'; the malware-family overlap with previously attributed Lazarus tooling supports a MEDIUM-confidence assessment of a DPRK nexus, not a confirmed one. SIGNBT communications use distinctive class-name/function-name C2 protocol prefixes (SIGNBTLG/SIGNBTKE/SIGNBTGC) with XOR/base64 and, in later variants, Curve25519 key exchange with ChaCha20 symmetric encryption; COPPERHEDGE stores its configuration in an NTFS alternate data stream and exposes roughly 30 C2 commands (0x2003-0x2032) with randomized HTTP parameter names for obfuscation. Precursor-campaign tooling in the same lineage (ThreatNeedle, wAgent, Agamemnon Downloader, LPEClient) used DLL side-loading (e.g., masquerading as PCAuditex.dll, spoolsv.exe/ualapi.dll hijacking), reflective/Tartarus-TpAllocInject loading, and RSA/AES key exchange.

For lateral movement and post-compromise operations inside victim networks, ASEC observed use of PsExec and Impacket (lateral movement/remote execution), Certipy and PetitPotam (Active Directory certificate-service abuse), TightVNC and a tool ASEC calls HookShot (interactive remote access), FileZilla, WinSCP, and Plink (data staging, exfiltration, and SSH tunneling), Socat and OpenSSH (reverse tunneling), UACMe (UAC-bypass privilege escalation), and Nircmd (silent command execution) — a toolkit largely composed of legitimate, dual-use administration software rather than bespoke offensive tooling, consistent with a defense-evasion strategy of blending into normal admin activity.

The advisory's most significant finding is the documented overlap between this state-sponsored actor and the Gunra ransomware group — a financially motivated, double-extortion ransomware operation (built on leaked Conti v2 source code, first observed publicly in April 2025) that encrypts files with a '.ENCRT' extension and drops a 'R3ADM3.txt' ransom note, negotiating via a Tor-hosted portal with a five-day payment deadline. ASEC identified identical vulnerability-exploitation patterns, matching SSH key fingerprints, shared C2 infrastructure (domains, IPs, and reverse-tunneling endpoints), and common anti-forensic techniques between the two clusters, suggesting either a shared-services relationship, tool/infrastructure leasing, or a degree of operational convergence between state-sponsored espionage activity and a nominally independent ransomware crew — a pattern consistent with prior CISA reporting (AA23-040a) on DPRK state actors using ransomware proceeds to help fund broader cyber operations.

Separately, ASEC's March 2026 Korean financial-sector threat report documents a related — and possibly overlapping — watering-hole campaign in which the 'AnySign4PC' financial security/browser-integration software was exploited for remote code execution, reused across multiple watering-hole distribution sites; no CVE identifier has been published for this flaw. The Operation Double Barrel advisory's own appendix (containing the campaign-specific IOC set: file hashes, domains, and IPs) was not accessible via public fetch at analysis time — the IOCs, malware-family details, and toolkit entries below are therefore drawn from the independently sourced malware-family and tooling literature (Operation SyncHole, CISA COPPERHEDGE MAR, Gunra ransomware research) that the advisory explicitly ties its Struggle/SIGNBT 3.0 and Brandoor/COPPERHEDGE naming to, and are documented as such rather than as confirmed Double-Barrel-specific artifacts.

## MITRE ATT&CK

- T1583 Acquire Infrastructure
- T1608 Stage Capabilities
- T1189 Drive-by Compromise
- T1566 Phishing
- T1190 Exploit Public-Facing Application
- T1195 Supply Chain Compromise
- T1204 User Execution
- T1218 System Binary Proxy Execution
- T1059 Command and Scripting Interpreter
- T1047 Windows Management Instrumentation
- T1574 Hijack Execution Flow
- T1547 Boot or Logon Autostart Execution
- T1548 Abuse Elevation Control Mechanism
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1620 Reflective Code Loading
- T1055 Process Injection
- T1564 Hide Artifacts
- T1622 Debugger Evasion
- T1098 Account Manipulation
- T1003 OS Credential Dumping
- T1649 Steal or Forge Authentication Certificates
- T1057 Process Discovery
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1021 Remote Services
- T1570 Lateral Tool Transfer
- T1071 Application Layer Protocol
- T1573 Encrypted Channel
- T1090 Proxy
- T1105 Ingress Tool Transfer
- T1048 Exfiltration Over Alternative Protocol
- T1041 Exfiltration Over C2 Channel
- T1486 Data Encrypted for Impact
- T1490 Inhibit System Recovery

## Sources

- [Joint Cybersecurity Advisory Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware Group)](https://asec.ahnlab.com/en/94696/)
- [A cascade of compromise: unveiling Lazarus' new campaign](https://securelist.com/unveiling-lazarus-new-campaign/110888/)
- [Operation SyncHole: Lazarus APT updates its toolset in watering hole attacks](https://securelist.com/operation-synchole-watering-hole-attacks-by-lazarus/116326/)
- [March 2026 Security Issues in the Korean & Global Financial Sector](https://asec.ahnlab.com/en/93421/)
- [MAR-10288834-1.v1 – North Korean Remote Access Tool: COPPERHEDGE](https://www.cisa.gov/ncas/analysis-reports/ar20-133a)
- [Gunra Ransomware – A Brief Analysis](https://www.cyfirma.com/research/gunra-ransomware-a-brief-analysis/)
- [N. Korean Lazarus Group Targets Software Vendor Using Known Flaws](https://thehackernews.com/2023/10/n-korean-lazarus-group-targets-software.html)
- [Lazarus hackers breached dev repeatedly to deploy SIGNBT malware](https://www.bleepingcomputer.com/news/security/lazarus-hackers-breached-dev-repeatedly-to-deploy-signbt-malware/)
- [South Korean Companies Targeted by Lazarus via Watering Hole Attacks, Zero-Days](https://www.securityweek.com/south-korean-companies-targeted-by-lazarus-via-watering-hole-attacks-zero-days/)
- [Kaspersky uncovers new Lazarus-led cyberattacks targeting South Korean supply chains](https://www.kaspersky.com/about/press-releases/kaspersky-uncovers-new-lazarus-led-cyberattacks-targeting-south-korean-supply-chains)
- [Gunra ransomware group profile](https://www.ransomlook.io/group/gunra)
- [CISA issues alert with South Korean government about DPRK's ransomware antics](https://malwarebytes.com/blog/news/2023/02/cisa-issues-alert-with-south-korean-government-about-dprks-ransomware-antics)
- [#StopRansomware: Ransomware Attacks on Critical Infrastructure Fund DPRK Malicious Cyber Activities](https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-040a)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1766
