Threat reportAPTTL-2026-1797
North Korea's Lazarus Group Linked to Tool-Sharing with Gunra Ransomware Operators Against South Korean Targets ("Operation Double Barrel")
North Korea's Lazarus Group Linked to Tool-Sharing with (TL-2026-1797), also tracked as Operation Double Barrel, is a high-severity advanced persistent threat campaign, first published 2026-07-31. It is attributed to Lazarus Group (North Korea) with medium confidence, affects Hancom AnySign4PC, maps to 28 MITRE ATT&CK techniques (T1003, T1005, T1021.004), and is covered by 9 detection rules and 27 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 28MITRE ATT&CK
- Actors
- 1Lazarus Group
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 27Indicators of compromise
Key facts for TL-2026-1797
- Threat ID
- TL-2026-1797
- Also known as
- Operation Double Barrel
- Severity
- HIGH
- Status
- ACTIVE
- Category
- APT
- First published
- Last reviewed
- Attribution
- Lazarus Group
- Attribution confidence
- MEDIUM
- Nation-state nexus
- North Korea
- Motivation
- ESPIONAGE
- Target sectors
- government administration, finance, cryptocurrency, information technology, health, news - media, education, manufacturing
- Target regions
- south korea, Asia-Pacific
- Detection rules
- 9
- Indicators of compromise
- 27
Malware and tooling in North Korea's Lazarus Group Linked to Tool-Sharing with
Malware and tooling: Agamemnon, Bankshot, LPEClient, PostNapTea, ThreatNeedle - S0665, gunra, wAgentTea, CCleaner, SDelete - S0195
How North Korea's Lazarus Group Linked to Tool-Sharing with works
A joint advisory from South Korea's NIS, NPA, KISA, and FSI, backed by AhnLab's ASEC technical report "Operation Double Barrel," documents parallel 2025-H1 2026 campaigns by the Lazarus Group and the Gunra ransomware operation that exploited the same buffer-overflow vulnerability in the mandatory financial security software AnySign4PC (Hancom) via watering-hole attacks on 15 legitimate Korean websites. AhnLab found a "likely technical link" -- identical malware filenames/execution arguments, shared privilege-escalation tooling, shared C2 infrastructure, and an identical SSH host-key fingerprint (Qr1to32lQHxEu6phzNyrTZrU0iElrOfVWMBLnqoen24) between a March 2026 Gunra intrusion at a compromised healthcare site and the state-sponsored espionage campaign -- but stopped short of concluding both are run by one actor.
AhnLab's ASEC and four South Korean government agencies (National Intelligence Service, National Police Agency, Korea Internet & Security Agency, and Financial Security Institute) published a joint cybersecurity advisory on 2026-07-30 titled 'Operation Double Barrel,' examining a technical overlap between a North Korean state-sponsored espionage campaign attributed to Lazarus Group and the Gunra ransomware-as-a-service operation. Both threat clusters exploited the same buffer-overflow remote-code-execution vulnerability in AnySign4PC (versions 1.1.4.4 through 1.1.4.6, fixed in 1.1.5.0), a Hancom-made security agent that is effectively mandatory for South Korean online banking, tax filing, and government-portal access. KISA issued a public patch notice on 2026-06-01, roughly six months after ENKI WhiteHat and AhnLab observed active exploitation beginning in the second half of 2025.
The exploit chain was delivered through 15 compromised legitimate Korean websites spanning media, healthcare, education, and manufacturing sectors, functioning as watering holes. Malicious JavaScript injected into real article/page content coordinated an exchange of four PNG images that carried encryption keys, performed version-fingerprinting of the victim's installed AnySign4PC build, delivered version-specific exploit code, and confirmed successful execution. A WebSocket channel to the locally running AnySign4PC process triggered the buffer overflow, and shellcode was injected into legitimate Microsoft processes (svchost.exe and SyncHost.exe) to generate a malicious DLL with no download prompt or user interaction. Depending on the intrusion, operators deployed the Struggle backdoor (an evolution of SIGNBT, observed at versions 0.0.1, 1.2, and 3.0) or the Brandoor backdoor (aliased to the COPPERHEDGE family), both supporting remote command execution, file theft, internal reconnaissance, and further payload delivery. Persistence was established via a scheduled task named 'RuntimeBroker' invoking task.vbs, and in at least one chain a renamed SSH client was persisted as SearchHost.exe to enable SSH-based lateral movement and reverse tunneling to 176.65.128.26. Payload staging used the domain jshosting.me. Operators used encrypted registry blobs and in-memory/reflective PE loading to avoid writing payloads to disk until a clean shutdown flushed them, and performed anti-forensic cleanup with SDelete and CCleaner plus renaming of temporary artifacts (net.tmp, inet.tmp) to random four-character names before deletion. AhnLab assesses that related activity touched at least 72 South Korean organizations in 2026, including government agencies, cryptocurrency exchanges, and IT service providers, though the 72 figure is not a tally of equally confirmed full compromises. This campaign is a continuation of the malware lineage AhnLab and Kaspersky previously documented in the related 2025 'Operation SyncHole' watering-hole campaign against South Korean financial, IT, semiconductor, software, and telecom firms, which used ThreatNeedle, wAgent, an early SignBT, CopperHedge, LPEClient, and the Agamemnon downloader against victims of the Cross EX and Innorix Agent mandatory software vulnerabilities -- distinct software from AnySign4PC but the same actor tradecraft pattern of weaponizing Korea's mandatory financial/government software ecosystem.
Gunra ransomware, unrelated in origin, emerged in April 2025 targeting five South Korean companies, built on leaked Conti v2 source code before the operator developed an independent payload. Gunra encrypts files with ChaCha20 (256-bit key, 96-bit nonce, 1MB chunks) protected by RSA-4096, appends the .ENCRT extension, drops a ransom note named R3ADM3.txt, and directs victims to a Tor payment portal at http://nsnhzysbntsqdwpys6mhml33muccsvterxewh5rkbmcab7bg2ttevjqd.onion. In January 2026 Gunra launched a formal RaaS affiliate program on the dark-web Ramp Forum offering cross-platform builders for Windows, Linux, ESXi, and NAS, and by 2026-03-09 CloudSEK had confirmed at least 32 victim organizations globally, gained largely via compromised VPN credentials sourced from infostealer logs and dark-web brokers plus spearphishing. The March 2026 Gunra intrusion at a compromised South Korean healthcare website that AhnLab flagged as technically overlapping with the Lazarus campaign used the same initial-access vulnerability, the same SyncHost.exe injection technique, the same SSH host-key fingerprint, and the same network infrastructure as the espionage operation -- a pattern AhnLab attributes to possible shared tooling, a common access broker, or limited collaboration between a nation-state actor and a criminal ransomware operation, rather than confirmed common ownership. No CVE identifier has been assigned to the AnySign4PC vulnerability as of 2026-07-30; the only publicly indexed CVE against the product, CVE-2020-7882, is an unrelated older directory-traversal flaw.
MITRE ATT&CK techniques used in TL-2026-1797
Credential Access
Collection
Lateral Movement
Defense Evasion
T1027.003 Steganography; T1036.003 Rename Legitimate Utilities; T1070.004 File Deletion; T1620 Reflective Code Loading
Exfiltration
T1041 Exfiltration Over C2 Channel
Persistence
Privilege Escalation
T1055 Process Injection; T1078 Valid Accounts
Execution
T1059.005 Visual Basic; T1204.002 Malicious File
Command and Control
T1071.001 Web Protocols; T1105 Ingress Tool Transfer; T1572 Protocol Tunneling
Discovery
T1082 System Information Discovery; T1083 File and Directory Discovery
defense-impairment
Initial Access
T1133 External Remote Services; T1189 Drive-by Compromise; T1190 Exploit Public-Facing Application; T1566.002 Spearphishing Link
Impact
T1486 Data Encrypted for Impact; T1657 Financial Theft
Resource Development
T1584.004 Server; T1608.001 Upload Malware
Reconnaissance
Affected products and versions in North Korea's Lazarus Group Linked to Tool-Sharing with
- Hancom — AnySign4PC
Vulnerable versions: 1.1.4.4; 1.1.4.5; 1.1.4.6
Fixed in: 1.1.5.0
Remediation for North Korea's Lazarus Group Linked to Tool-Sharing with
Patches
- Apply the KISA-mandated AnySign4PC upgrade to v1.1.5.0, which fixes the buffer-overflow RCE present in v1.1.4.4-1.1.4.6
Immediate actions
- Uninstall or upgrade AnySign4PC to version 1.1.5.0 or later on all endpoints per KISA's 2026-06-01 advisory
- Block C2 IP 176.65.128.26 and domain jshosting.me at network perimeter and DNS resolvers
- Hunt for scheduled tasks named 'RuntimeBroker' invoking task.vbs and for renamed SSH clients masquerading as SearchHost.exe
- Isolate and forensically image hosts showing SyncHost.exe/svchost.exe process injection or unexplained in-memory PE execution
Workarounds
- Where uninstalling mandatory financial security software is not feasible, restrict its use to isolated/segmented workstations and disable auto-invocation on browser page navigation
Longer-term hardening
- Deploy EDR with behavioral detection for process injection and reflective/in-memory PE loading rather than relying on signature-based AV alone
- Audit and minimize the footprint of mandatory Korean financial security software; segment systems that must run legacy security agents from high-value assets
- Establish continuous integrity monitoring for public-facing media, healthcare, education, and manufacturing-sector websites at risk of watering-hole compromise
- Track SSH host-key fingerprints and C2 infrastructure reuse across incidents to detect shared-tooling/access-broker relationships between distinct threat actors
Weaknesses (CWE) in North Korea's Lazarus Group Linked to Tool-Sharing with
Timeline of North Korea's Lazarus Group Linked to Tool-Sharing with
- Gunra ransomware emerges, built on leaked Conti v2 source code, initially targeting five South Korean companies.
- ENKI WhiteHat and AhnLab observe the AnySign4PC buffer-overflow vulnerability being actively exploited beginning in the second half of 2025.
- Gunra launches a formal RaaS affiliate program on the dark-web Ramp Forum, offering cross-platform ransomware builders for Windows, Linux, ESXi, and NAS.
- A Gunra ransomware intrusion at a compromised South Korean healthcare website shows technical overlap with the state-sponsored campaign: same vulnerability, same SyncHost.exe process-injection technique, same SSH host-key fingerprint, and same network infrastructure.
- CloudSEK confirms at least 32 total Gunra ransomware victim organizations globally.
- AhnLab separately attributes the March 2026 AnySign4PC watering-hole attack directly to Lazarus Group.
- KISA issues a public security notice identifying AnySign4PC versions 1.1.4.4-1.1.4.6 as vulnerable to a buffer overflow permitting remote code execution, with 1.1.5.0 as the fixed release.
- AhnLab ASEC and a joint South Korean advisory (NIS, NPA, KISA, FSI) publish the 'Operation Double Barrel' report documenting a likely technical link between Lazarus and Gunra; reporting states Lazarus deployed espionage backdoors against at least 72 South Korean organizations in 2026 and compromised 15 legitimate websites for watering-hole attacks.
Sources cited for North Korea's Lazarus Group Linked to Tool-Sharing with
- North Korea's Lazarus Group sharing tools with ransomware hackers, South Korean agencies warn
- Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts
- State Hackers Made South Korea's Mandatory Banking Software Into Zero-Day Weapon
- Joint Cybersecurity Advisory: Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware Group)
- [합동 사이버 보안 권고문] Operation Double Barrel (국가배후 해킹조직과 Gunra 랜섬웨어 그룹의 관계)
- AhnLab Cyber Threat Intelligence Report: Operation Double Barrel (ENG)
- South Korean Companies Targeted by Lazarus via Watering Hole Attacks, Zero-Days (Operation SyncHole)
- Inside Gunra RaaS: From Affiliate Recruitment on the Dark Web to Full Technical Dissection of their Locker
- Gunra Ransomware Expands RaaS Operations After Shifting From Conti-Based Locker
- Gunra ransomware Analysis, Overview
- Lazarus Group, Labyrinth Chollima, HIDDEN COBRA, Guardians of Peace, ZINC, NICKEL ACADEMY, Diamond Sleet, Group G0032
- Anysign4pc Security Vulnerabilities and Issues -- Anysign4pc CVE List
Detection coverage for TL-2026-1797
As of 2026-07-31, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1797 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-1797
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.