North Korea's Lazarus Group Implicated in Ransomware Attacks on South Korea, Sharing Tools and Infrastructure
New research suggests a concerning collaboration or shared infrastructure between North Korea's state-sponsored **Lazarus Group** and the **Gunra** ransomware operation. Both entities have targeted South Korean organizations, exploiting identical vulnerabilities and employing similar tactics, raising alarms among cybersecurity professionals and privacy-conscious users.
A new joint advisory from four South Korean security and intelligence agencies, alongside a technical report from cybersecurity firm **AhnLab**, reveals a troubling convergence of tactics between North Korea's notorious **Lazarus Group** and the **Gunra** ransomware scheme.
The findings indicate that these groups ran parallel campaigns against South Korean targets from 2025 through the first half of this year, differing primarily in their ultimate objectives.
### Shared Vulnerabilities and Tools
Both **Lazarus** and **Gunra** exploited the same vulnerabilities in Korean financial security software products, which are effectively mandatory for anyone utilizing Korean banking or government services. While **Lazarus** has focused on installing espionage backdoors in at least 72 organizations in 2026 aloneβincluding government agencies, cryptocurrency exchanges, and IT service providersβ**Gunra** has leveraged its access for file encryption, data exfiltration, and extortion demands.
**AhnLab**'s report highlights striking similarities in their operational methods:
* Identical malware filenames and execution arguments.
* The same privilege escalation tools.
* Shared command-and-control servers.
* An identical SSH key fingerprintβa unique cryptographic identifier.
* Even their malware deletion methods were the same, renaming files to random four-character strings before wiping them.
### Operation Double Barrel and Watering-Hole Attacks
**AhnLab** has dubbed this campaign "Operation Double Barrel," though it refrains from definitively attributing both campaigns to a single actor. The overlaps, however, suggest a "high likelihood of technical linkage," pointing to potential collaboration, shared infrastructure, or access brokering.
As part of their campaigns, the attackers compromised 15 legitimate Korean websites across various industries. These sites were then used for watering-hole attacks, redirecting selected visitors to specific infrastructure that triggered software flaws and injected malicious code into legitimate **Microsoft** processes.
### Spearphishing and AI Lures
Beyond watering-hole attacks, the attackers also conducted spearphishing campaigns. One notable instance targeted a Korean defense company with emails disguised as a survey about GaN semiconductors. **AhnLab** observed that some of the lure pages appeared to have been generated using AI.
The report also identified multiple websites used for watering-hole attacks managed by the same Korean website development company. **AhnLab** assesses that the attackers likely compromised the hosting provider first, then expanded access to client sites through the development companyβs management system, rather than hacking each site individually.
### Growing Entanglement with Ransomware
These findings add to increasing evidence of Pyongyang-backed hackers deepening their involvement with the ransomware ecosystem. Over the past 18 months, different North Korean state-sponsored actors have been linked to **Play**, **Qilin**, and **Medusa** ransomware operations by researchers at **Palo Alto Networks**, **Microsoft**, and **Symantec**, respectively.
This trend was further highlighted in 2024 when the U.S. Department of Justice unsealed an indictment against **Rim Jong Hyok**, an alleged member of North Korea's **Andariel Unit**, for his purported role in ransomware attacks on U.S. hospitals.
### A New Dynamic: State-Sponsored Supply Chain?
The **Gunra** connection, however, may represent a shift in this dynamic. Previous instances often involved North Korean operators joining established criminal franchises as affiliates. Here, the evidence suggests the relationship might be inverted, with state-backed hackers potentially supplying tools, exploits, and access to a smaller, newer group.
**Gunra** emerged in April 2025, initially targeting five South Korean companies. The group built its ransomware on leaked **Conti v2** source code before transitioning to a ransomware-as-a-service (RaaS) model in January of this year. Prior to **AhnLab**'s report, industry researchers had tentatively linked **Gunra** to Eastern European operators based on its **Conti** heritage.
As of March 2026, **Gunra** had claimed at least 32 victims globally across healthcare, manufacturing, IT, and other sectors, operating a double-extortion model by exfiltrating data before encryption and threatening to publish it on a Tor-based leak site.
### Widespread Risk for Users and Organizations
**AhnLab** warns that the risk extends beyond explicitly targeted organizations.
"The Korean financial security software currently being abused⦠is used not only in various enterprise environments but also on many personal PCs," the company stated.
"Because the vulnerabilities can be triggered simply when a user accesses a specific page, not only explicitly targeted organizations but also general user environments running vulnerable software may be exposed to risk."
Individuals and organizations are urged to take defensive measures, particularly ensuring security software is up-to-date, as infection can occur simply by visiting a compromised legitimate website.