Threat reportAPTTL-2026-1797

North Korea's Lazarus Group Linked to Tool-Sharing with Gunra Ransomware Operators Against South Korean Targets ("Operation Double Barrel")

highACTIVE

North Korea's Lazarus Group Linked to Tool-Sharing with (TL-2026-1797), also tracked as Operation Double Barrel, is a high-severity advanced persistent threat campaign, first published 2026-07-31. It is attributed to Lazarus Group (North Korea) with medium confidence, affects Hancom AnySign4PC, maps to 28 MITRE ATT&CK techniques (T1003, T1005, T1021.004), and is covered by 9 detection rules and 27 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
28MITRE ATT&CK
Actors
1Lazarus Group
Detection rules
9SPL · KQL · Sigma
IOCs
27Indicators of compromise

Key facts for TL-2026-1797

Threat ID
TL-2026-1797
Also known as
Operation Double Barrel
Severity
HIGH
Status
ACTIVE
Category
APT
First published
Last reviewed
Attribution
Lazarus Group
Attribution confidence
MEDIUM
Nation-state nexus
North Korea
Motivation
ESPIONAGE
Target sectors
government administration, finance, cryptocurrency, information technology, health, news - media, education, manufacturing
Target regions
south korea, Asia-Pacific
Detection rules
9
Indicators of compromise
27

Malware and tooling in North Korea's Lazarus Group Linked to Tool-Sharing with

Malware and tooling: Agamemnon, Bankshot, LPEClient, PostNapTea, ThreatNeedle - S0665, gunra, wAgentTea, CCleaner, SDelete - S0195

How North Korea's Lazarus Group Linked to Tool-Sharing with works

A joint advisory from South Korea's NIS, NPA, KISA, and FSI, backed by AhnLab's ASEC technical report "Operation Double Barrel," documents parallel 2025-H1 2026 campaigns by the Lazarus Group and the Gunra ransomware operation that exploited the same buffer-overflow vulnerability in the mandatory financial security software AnySign4PC (Hancom) via watering-hole attacks on 15 legitimate Korean websites. AhnLab found a "likely technical link" -- identical malware filenames/execution arguments, shared privilege-escalation tooling, shared C2 infrastructure, and an identical SSH host-key fingerprint (Qr1to32lQHxEu6phzNyrTZrU0iElrOfVWMBLnqoen24) between a March 2026 Gunra intrusion at a compromised healthcare site and the state-sponsored espionage campaign -- but stopped short of concluding both are run by one actor.

AhnLab's ASEC and four South Korean government agencies (National Intelligence Service, National Police Agency, Korea Internet & Security Agency, and Financial Security Institute) published a joint cybersecurity advisory on 2026-07-30 titled 'Operation Double Barrel,' examining a technical overlap between a North Korean state-sponsored espionage campaign attributed to Lazarus Group and the Gunra ransomware-as-a-service operation. Both threat clusters exploited the same buffer-overflow remote-code-execution vulnerability in AnySign4PC (versions 1.1.4.4 through 1.1.4.6, fixed in 1.1.5.0), a Hancom-made security agent that is effectively mandatory for South Korean online banking, tax filing, and government-portal access. KISA issued a public patch notice on 2026-06-01, roughly six months after ENKI WhiteHat and AhnLab observed active exploitation beginning in the second half of 2025.

The exploit chain was delivered through 15 compromised legitimate Korean websites spanning media, healthcare, education, and manufacturing sectors, functioning as watering holes. Malicious JavaScript injected into real article/page content coordinated an exchange of four PNG images that carried encryption keys, performed version-fingerprinting of the victim's installed AnySign4PC build, delivered version-specific exploit code, and confirmed successful execution. A WebSocket channel to the locally running AnySign4PC process triggered the buffer overflow, and shellcode was injected into legitimate Microsoft processes (svchost.exe and SyncHost.exe) to generate a malicious DLL with no download prompt or user interaction. Depending on the intrusion, operators deployed the Struggle backdoor (an evolution of SIGNBT, observed at versions 0.0.1, 1.2, and 3.0) or the Brandoor backdoor (aliased to the COPPERHEDGE family), both supporting remote command execution, file theft, internal reconnaissance, and further payload delivery. Persistence was established via a scheduled task named 'RuntimeBroker' invoking task.vbs, and in at least one chain a renamed SSH client was persisted as SearchHost.exe to enable SSH-based lateral movement and reverse tunneling to 176.65.128.26. Payload staging used the domain jshosting.me. Operators used encrypted registry blobs and in-memory/reflective PE loading to avoid writing payloads to disk until a clean shutdown flushed them, and performed anti-forensic cleanup with SDelete and CCleaner plus renaming of temporary artifacts (net.tmp, inet.tmp) to random four-character names before deletion. AhnLab assesses that related activity touched at least 72 South Korean organizations in 2026, including government agencies, cryptocurrency exchanges, and IT service providers, though the 72 figure is not a tally of equally confirmed full compromises. This campaign is a continuation of the malware lineage AhnLab and Kaspersky previously documented in the related 2025 'Operation SyncHole' watering-hole campaign against South Korean financial, IT, semiconductor, software, and telecom firms, which used ThreatNeedle, wAgent, an early SignBT, CopperHedge, LPEClient, and the Agamemnon downloader against victims of the Cross EX and Innorix Agent mandatory software vulnerabilities -- distinct software from AnySign4PC but the same actor tradecraft pattern of weaponizing Korea's mandatory financial/government software ecosystem.

Gunra ransomware, unrelated in origin, emerged in April 2025 targeting five South Korean companies, built on leaked Conti v2 source code before the operator developed an independent payload. Gunra encrypts files with ChaCha20 (256-bit key, 96-bit nonce, 1MB chunks) protected by RSA-4096, appends the .ENCRT extension, drops a ransom note named R3ADM3.txt, and directs victims to a Tor payment portal at http://nsnhzysbntsqdwpys6mhml33muccsvterxewh5rkbmcab7bg2ttevjqd.onion. In January 2026 Gunra launched a formal RaaS affiliate program on the dark-web Ramp Forum offering cross-platform builders for Windows, Linux, ESXi, and NAS, and by 2026-03-09 CloudSEK had confirmed at least 32 victim organizations globally, gained largely via compromised VPN credentials sourced from infostealer logs and dark-web brokers plus spearphishing. The March 2026 Gunra intrusion at a compromised South Korean healthcare website that AhnLab flagged as technically overlapping with the Lazarus campaign used the same initial-access vulnerability, the same SyncHost.exe injection technique, the same SSH host-key fingerprint, and the same network infrastructure as the espionage operation -- a pattern AhnLab attributes to possible shared tooling, a common access broker, or limited collaboration between a nation-state actor and a criminal ransomware operation, rather than confirmed common ownership. No CVE identifier has been assigned to the AnySign4PC vulnerability as of 2026-07-30; the only publicly indexed CVE against the product, CVE-2020-7882, is an unrelated older directory-traversal flaw.

MITRE ATT&CK techniques used in TL-2026-1797

Credential Access

T1003 OS Credential Dumping

Collection

T1005 Data from Local System

Lateral Movement

T1021.004 SSH

Defense Evasion

T1027.003 Steganography; T1036.003 Rename Legitimate Utilities; T1070.004 File Deletion; T1620 Reflective Code Loading

Exfiltration

T1041 Exfiltration Over C2 Channel

Persistence

T1053.005 Scheduled Task

Privilege Escalation

T1055 Process Injection; T1078 Valid Accounts

Execution

T1059.005 Visual Basic; T1204.002 Malicious File

Command and Control

T1071.001 Web Protocols; T1105 Ingress Tool Transfer; T1572 Protocol Tunneling

Discovery

T1082 System Information Discovery; T1083 File and Directory Discovery

defense-impairment

T1112 Modify Registry

Initial Access

T1133 External Remote Services; T1189 Drive-by Compromise; T1190 Exploit Public-Facing Application; T1566.002 Spearphishing Link

Impact

T1486 Data Encrypted for Impact; T1657 Financial Theft

Resource Development

T1584.004 Server; T1608.001 Upload Malware

Reconnaissance

T1595.002 Vulnerability Scanning

Affected products and versions in North Korea's Lazarus Group Linked to Tool-Sharing with

  • Hancom — AnySign4PC
    Vulnerable versions: 1.1.4.4; 1.1.4.5; 1.1.4.6
    Fixed in: 1.1.5.0

Remediation for North Korea's Lazarus Group Linked to Tool-Sharing with

Patches

  • Apply the KISA-mandated AnySign4PC upgrade to v1.1.5.0, which fixes the buffer-overflow RCE present in v1.1.4.4-1.1.4.6

Immediate actions

  • Uninstall or upgrade AnySign4PC to version 1.1.5.0 or later on all endpoints per KISA's 2026-06-01 advisory
  • Block C2 IP 176.65.128.26 and domain jshosting.me at network perimeter and DNS resolvers
  • Hunt for scheduled tasks named 'RuntimeBroker' invoking task.vbs and for renamed SSH clients masquerading as SearchHost.exe
  • Isolate and forensically image hosts showing SyncHost.exe/svchost.exe process injection or unexplained in-memory PE execution

Workarounds

  • Where uninstalling mandatory financial security software is not feasible, restrict its use to isolated/segmented workstations and disable auto-invocation on browser page navigation

Longer-term hardening

  • Deploy EDR with behavioral detection for process injection and reflective/in-memory PE loading rather than relying on signature-based AV alone
  • Audit and minimize the footprint of mandatory Korean financial security software; segment systems that must run legacy security agents from high-value assets
  • Establish continuous integrity monitoring for public-facing media, healthcare, education, and manufacturing-sector websites at risk of watering-hole compromise
  • Track SSH host-key fingerprints and C2 infrastructure reuse across incidents to detect shared-tooling/access-broker relationships between distinct threat actors

Weaknesses (CWE) in North Korea's Lazarus Group Linked to Tool-Sharing with

CWE-120

Timeline of North Korea's Lazarus Group Linked to Tool-Sharing with

  • Gunra ransomware emerges, built on leaked Conti v2 source code, initially targeting five South Korean companies.
  • ENKI WhiteHat and AhnLab observe the AnySign4PC buffer-overflow vulnerability being actively exploited beginning in the second half of 2025.
  • Gunra launches a formal RaaS affiliate program on the dark-web Ramp Forum, offering cross-platform ransomware builders for Windows, Linux, ESXi, and NAS.
  • A Gunra ransomware intrusion at a compromised South Korean healthcare website shows technical overlap with the state-sponsored campaign: same vulnerability, same SyncHost.exe process-injection technique, same SSH host-key fingerprint, and same network infrastructure.
  • CloudSEK confirms at least 32 total Gunra ransomware victim organizations globally.
  • AhnLab separately attributes the March 2026 AnySign4PC watering-hole attack directly to Lazarus Group.
  • KISA issues a public security notice identifying AnySign4PC versions 1.1.4.4-1.1.4.6 as vulnerable to a buffer overflow permitting remote code execution, with 1.1.5.0 as the fixed release.
  • AhnLab ASEC and a joint South Korean advisory (NIS, NPA, KISA, FSI) publish the 'Operation Double Barrel' report documenting a likely technical link between Lazarus and Gunra; reporting states Lazarus deployed espionage backdoors against at least 72 South Korean organizations in 2026 and compromised 15 legitimate websites for watering-hole attacks.

Sources cited for North Korea's Lazarus Group Linked to Tool-Sharing with

Detection coverage for TL-2026-1797

As of 2026-07-31, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1797 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
27 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-1797

1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats