North Korea's Lazarus Group Linked to Tool-Sharing with Gunra Ransomware Operators Against South Korean Targets ("Operation Double Barrel") — Threadlinqs Intelligence
As of 2026-07-31, North Korea's Lazarus Group Linked to Tool-Sharing with Gunra Ransomware Operators Against South Korean Targets ("Operation Double Barrel") is a high-severity apt threat attributed to Lazarus Group (North Korea), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 27 indicators of compromise.
Threat ID: TL-2026-1797 · Severity: HIGH · Status: ACTIVE · Category: APT
Attribution: Lazarus Group · North Korea · ESPIONAGE
A joint advisory from South Korea's NIS, NPA, KISA, and FSI, backed by AhnLab's ASEC technical report "Operation Double Barrel," documents parallel 2025-H1 2026 campaigns by the Lazarus Group and the
AhnLab's ASEC and four South Korean government agencies (National Intelligence Service, National Police Agency, Korea Internet & Security Agency, and Financial Security Institute) published a joint cybersecurity advisory on 2026-07-30 titled 'Operation Double Barrel,' examining a technical overlap between a North Korean state-sponsored espionage campaign attributed to Lazarus Group and the Gunra ransomware-as-a-service operation. Both threat clusters exploited the same buffer-overflow remote-code-execution vulnerability in AnySign4PC (versions 1.1.4.4 through 1.1.4.6, fixed in 1.1.5.0), a Hancom-made security agent that is effectively mandatory for South Korean online banking, tax filing, and government-portal access. KISA issued a public patch notice on 2026-06-01, roughly six months after ENKI WhiteHat and AhnLab observed active exploitation beginning in the second half of 2025.
The exploit chain was delivered through 15 compromised legitimate Korean websites spanning media, healthcare, education, and manufacturing sectors, functioning as watering holes. Malicious JavaScript injected into real article/page content coordinated an exchange of four PNG images that carried encryption keys, performed version-fingerprinting of the victim's installed AnySign4PC build, delivered version-specific exploit code, and confirmed successful execution. A WebSocket channel to the locally running AnySign4PC process triggered the buffer overflow, and shellcode was injected into legitimate Microsoft processes (svchost.exe and SyncHost.exe) to generate a malicious DLL with no download prompt or user interaction. Depending on the intrusion, operators deployed the Struggle backdoor (an evolution of SIGNBT, observed at versions 0.0.1, 1.2, and 3.0) or the Brandoor backdoor (aliased to the COPPERHEDGE family), both supporting remote command execution, file theft, internal reconnaissance, and further payload delivery. Persistence was established via a scheduled task named 'RuntimeBroker' invoking task.vbs, and in at least one chain a renamed SSH client was persisted as SearchHost.exe to enable SSH-based lateral movement and reverse tunneling to 176.65.128.26. Payload staging used the domain jshosting.me. Operators used encrypted registry blobs and in-memory/reflective PE loading to avoid writing payloads to disk until a clean shutdown flushed them, and performed anti-forensic cleanup with SDelete and CCleaner plus renaming of temporary artifacts (net.tmp, inet.tmp) to random four-character names before deletion. AhnLab assesses that related activity touched at least 72 South Korean organizations in 2026, including government agencies, cryptocurrency exchanges, and IT service providers, though the 72 figure is not a tally of equally confirmed full compromises. This campaign is a continuation of the malware lineage AhnLab and Kaspersky previously documented in the related 2025 'Operation SyncHole' watering-hole campaign against South Korean financial, IT, semiconductor, software, and telecom firms, which used ThreatNeedle, wAgent, an early SignBT, CopperHedge, LPEClient, and the Agamemnon downloader against victims of the Cross EX and Innorix Agent mandatory software vulnerabilities -- distinct software from AnySign4PC but the same actor tradecraft pattern of weaponizing Korea's mandatory financial/government software ecosystem.
Gunra ransomware, unrelated in origin, emerged in April 2025 targeting five South Korean companies, built on leaked Conti v2 source code before the operator developed an independent payload. Gunra encrypts files with ChaCha20 (256-bit key, 96-bit nonce, 1MB chunks) protected by RSA-4096, appends the .ENCRT extension, drops a ransom note named R3ADM3.txt, and directs victims to a Tor payment portal at http://nsnhzysbntsqdwpys6mhml33muccsvterxewh5rkbmcab7bg2ttevjqd.onion. In January 2026 Gunra launched a formal RaaS affiliate program on the dark-web Ramp Forum offering cross-platform builders for Windows, Linux, ESXi, and NAS,
Target sectors: government administration, finance, cryptocurrency, information technology, health, news - media, education, manufacturing
Target regions: south korea, Asia-Pacific
References
- North Korea's Lazarus Group sharing tools with ransomware hackers, South Korean agencies warn
- Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts
- State Hackers Made South Korea's Mandatory Banking Software Into Zero-Day Weapon
- Joint Cybersecurity Advisory: Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware Group)
- [합동 사이버 보안 권고문] Operation Double Barrel (국가배후 해킹조직과 Gunra 랜섬웨어 그룹의 관계)
- AhnLab Cyber Threat Intelligence Report: Operation Double Barrel (ENG)
- South Korean Companies Targeted by Lazarus via Watering Hole Attacks, Zero-Days (Operation SyncHole)
- Inside Gunra RaaS: From Affiliate Recruitment on the Dark Web to Full Technical Dissection of their Locker
- Gunra Ransomware Expands RaaS Operations After Shifting From Conti-Based Locker
- Gunra ransomware Analysis, Overview
- Lazarus Group, Labyrinth Chollima, HIDDEN COBRA, Guardians of Peace, ZINC, NICKEL ACADEMY, Diamond Sleet, Group G0032
- Anysign4pc Security Vulnerabilities and Issues -- Anysign4pc CVE List
Detections & IOCs
As of 2026-08-25, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 27 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
APT, HIGH, threat intelligence, cybersecurity, T1595.002, T1584.004, T1608.001, T1189, T1566.002, T1190, T1133, T1059.005, T1204.002, T1053.005