# North Korea's Lazarus Group Linked to Tool-Sharing with Gunra Ransomware Operators Against South Korean Targets ("Operation Double Barrel")

> A joint advisory from South Korea's NIS, NPA, KISA, and FSI, backed by AhnLab's ASEC technical report "Operation Double Barrel," documents parallel 2025-H1 2026 campaigns by the Lazarus Group and the Gunra ransomware operation that exploited the same buffer-overflow vulnerability in the mandatory financial security software AnySign4PC (Hancom) via watering-hole attacks on 15 legitimate Korean websites. AhnLab found a "likely technical link" -- identical malware filenames/execution arguments, shared privilege-escalation tooling, shared C2 infrastructure, and an identical SSH host-key fingerprint (Qr1to32lQHxEu6phzNyrTZrU0iElrOfVWMBLnqoen24) between a March 2026 Gunra intrusion at a compromised healthcare site and the state-sponsored espionage campaign -- but stopped short of concluding both are run by one actor.

- **Published:** 2026-07-31T00:00:00Z
- **Last reviewed:** 2026-07-31T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1797
- **ID:** TL-2026-1797
- **Severity:** HIGH
- **Category:** APT
- **Status:** ACTIVE
- **Actor:** Lazarus Group (North Korea)
- **Detections:** 9 · **IOCs:** 27 (full data via the Threadlinqs MCP server — Purple tier)

## Description

AhnLab's ASEC and four South Korean government agencies (National Intelligence Service, National Police Agency, Korea Internet & Security Agency, and Financial Security Institute) published a joint cybersecurity advisory on 2026-07-30 titled 'Operation Double Barrel,' examining a technical overlap between a North Korean state-sponsored espionage campaign attributed to Lazarus Group and the Gunra ransomware-as-a-service operation. Both threat clusters exploited the same buffer-overflow remote-code-execution vulnerability in AnySign4PC (versions 1.1.4.4 through 1.1.4.6, fixed in 1.1.5.0), a Hancom-made security agent that is effectively mandatory for South Korean online banking, tax filing, and government-portal access. KISA issued a public patch notice on 2026-06-01, roughly six months after ENKI WhiteHat and AhnLab observed active exploitation beginning in the second half of 2025.

The exploit chain was delivered through 15 compromised legitimate Korean websites spanning media, healthcare, education, and manufacturing sectors, functioning as watering holes. Malicious JavaScript injected into real article/page content coordinated an exchange of four PNG images that carried encryption keys, performed version-fingerprinting of the victim's installed AnySign4PC build, delivered version-specific exploit code, and confirmed successful execution. A WebSocket channel to the locally running AnySign4PC process triggered the buffer overflow, and shellcode was injected into legitimate Microsoft processes (svchost.exe and SyncHost.exe) to generate a malicious DLL with no download prompt or user interaction. Depending on the intrusion, operators deployed the Struggle backdoor (an evolution of SIGNBT, observed at versions 0.0.1, 1.2, and 3.0) or the Brandoor backdoor (aliased to the COPPERHEDGE family), both supporting remote command execution, file theft, internal reconnaissance, and further payload delivery. Persistence was established via a scheduled task named 'RuntimeBroker' invoking task.vbs, and in at least one chain a renamed SSH client was persisted as SearchHost.exe to enable SSH-based lateral movement and reverse tunneling to 176.65.128.26. Payload staging used the domain jshosting.me. Operators used encrypted registry blobs and in-memory/reflective PE loading to avoid writing payloads to disk until a clean shutdown flushed them, and performed anti-forensic cleanup with SDelete and CCleaner plus renaming of temporary artifacts (net.tmp, inet.tmp) to random four-character names before deletion. AhnLab assesses that related activity touched at least 72 South Korean organizations in 2026, including government agencies, cryptocurrency exchanges, and IT service providers, though the 72 figure is not a tally of equally confirmed full compromises. This campaign is a continuation of the malware lineage AhnLab and Kaspersky previously documented in the related 2025 'Operation SyncHole' watering-hole campaign against South Korean financial, IT, semiconductor, software, and telecom firms, which used ThreatNeedle, wAgent, an early SignBT, CopperHedge, LPEClient, and the Agamemnon downloader against victims of the Cross EX and Innorix Agent mandatory software vulnerabilities -- distinct software from AnySign4PC but the same actor tradecraft pattern of weaponizing Korea's mandatory financial/government software ecosystem.

Gunra ransomware, unrelated in origin, emerged in April 2025 targeting five South Korean companies, built on leaked Conti v2 source code before the operator developed an independent payload. Gunra encrypts files with ChaCha20 (256-bit key, 96-bit nonce, 1MB chunks) protected by RSA-4096, appends the .ENCRT extension, drops a ransom note named R3ADM3.txt, and directs victims to a Tor payment portal at http://nsnhzysbntsqdwpys6mhml33muccsvterxewh5rkbmcab7bg2ttevjqd.onion. In January 2026 Gunra launched a formal RaaS affiliate program on the dark-web Ramp Forum offering cross-platform builders for Windows, Linux, ESXi, and NAS, and by 2026-03-09 CloudSEK had confirmed at least 32 victim organizations globally, gained largely via compromised VPN credentials sourced from infostealer logs and dark-web brokers plus spearphishing. The March 2026 Gunra intrusion at a compromised South Korean healthcare website that AhnLab flagged as technically overlapping with the Lazarus campaign used the same initial-access vulnerability, the same SyncHost.exe injection technique, the same SSH host-key fingerprint, and the same network infrastructure as the espionage operation -- a pattern AhnLab attributes to possible shared tooling, a common access broker, or limited collaboration between a nation-state actor and a criminal ransomware operation, rather than confirmed common ownership. No CVE identifier has been assigned to the AnySign4PC vulnerability as of 2026-07-30; the only publicly indexed CVE against the product, CVE-2020-7882, is an unrelated older directory-traversal flaw.

## MITRE ATT&CK

- T1595.002 Vulnerability Scanning
- T1584.004 Server
- T1608.001 Upload Malware
- T1189 Drive-by Compromise
- T1566.002 Spearphishing Link
- T1190 Exploit Public-Facing Application
- T1133 External Remote Services
- T1059.005 Visual Basic
- T1204.002 Malicious File
- T1053.005 Scheduled Task
- T1055 Process Injection
- T1078 Valid Accounts
- T1036.003 Rename Legitimate Utilities
- T1027.003 Steganography
- T1112 Modify Registry
- T1070.004 File Deletion
- T1620 Reflective Code Loading
- T1003 OS Credential Dumping
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1021.004 SSH
- T1005 Data from Local System
- T1041 Exfiltration Over C2 Channel
- T1105 Ingress Tool Transfer
- T1071.001 Web Protocols
- T1572 Protocol Tunneling
- T1486 Data Encrypted for Impact
- T1657 Financial Theft

## Sources

- [North Korea's Lazarus Group sharing tools with ransomware hackers, South Korean agencies warn](https://therecord.media/north-korea-hackers-ransomware)
- [Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts](https://thehackernews.com/2026/07/hackers-exploit-anysign4pc-via-hacked.html)
- [State Hackers Made South Korea's Mandatory Banking Software Into Zero-Day Weapon](https://www.techtimes.com/articles/322157/20260730/state-hackers-made-south-koreas-mandatory-banking-software-zero-day-weapon.htm)
- [Joint Cybersecurity Advisory: Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware Group)](https://www.hendryadrian.com/joint-cybersecurity-advisory-operation-double-barrel-the-relationship-between-a-state-sponsored-threat-actor-and-the-gunra-ransomware-group/)
- [합동 사이버 보안 권고문 Operation Double Barrel (국가배후 해킹조직과 Gunra 랜섬웨어 그룹의 관계)](https://asec.ahnlab.com/ko/94695/)
- [AhnLab Cyber Threat Intelligence Report: Operation Double Barrel (ENG)](https://image.ahnlab.com/atip/content/file/20260730/[AhnLab]Operation%20Double%20Barrel(ENG)(2026.07.30).pdf)
- [South Korean Companies Targeted by Lazarus via Watering Hole Attacks, Zero-Days (Operation SyncHole)](https://www.securityweek.com/south-korean-companies-targeted-by-lazarus-via-watering-hole-attacks-zero-days/)
- [Inside Gunra RaaS: From Affiliate Recruitment on the Dark Web to Full Technical Dissection of their Locker](https://www.cloudsek.com/blog/inside-gunra-raas-from-affiliate-recruitment-on-the-dark-web-to-full-technical-dissection-of-their-locker)
- [Gunra Ransomware Expands RaaS Operations After Shifting From Conti-Based Locker](https://cybersecuritynews.com/gunra-ransomware-expands-raas-operations/)
- [Gunra ransomware Analysis, Overview](https://any.run/malware-trends/gunra/)
- [Lazarus Group, Labyrinth Chollima, HIDDEN COBRA, Guardians of Peace, ZINC, NICKEL ACADEMY, Diamond Sleet, Group G0032](https://attack.mitre.org/groups/G0032/)
- [Anysign4pc Security Vulnerabilities and Issues -- Anysign4pc CVE List](https://vulners.com/search/vendors/hancom/products/anysign4pc)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1797
