BTC$63,057+0.34% LTC$44.05+1.12% XMR$412.08+4.33%
TorPortal TorPortalMarkets, mirrors, dark web news
The Record · Jul 30, 2026 · 4 min read · Original story

North Korea’s Lazarus Group sharing tools with ransomware hackers, South Korean agencies warn

North Korea’s Lazarus Group sharing tools with ransomware hackers, South Korean agencies warn
North Korea’s Lazarus Group sharing tools with ransomware hackers, South Korean agencies warn

Cyberattack tools and infrastructure used by North Korea’s Lazarus Group appear to have been shared with ransomware criminals targeting South Korean organizations, according to new research released Thursday alongside a joint advisory by four South Korean security and intelligence agencies.

The technical report from cybersecurity firm AhnLab details how the state-sponsored North Korean group, widely tracked as Lazarus, and the Gunra ransomware scheme ran parallel campaigns against South Korean targets from 2025 through the first half of this year, differing only in their final objective.

Both groups exploited the same vulnerabilities in Korean financial security software products that are effectively mandatory for anyone using Korean banking or government services. Where the Lazarus hackers have installed espionage backdoors in at least 72 organizations in 2026 alone — including government agencies, cryptocurrency exchanges, and IT service providers — Gunra has instead used its access to encrypt files, steal data and demand an extortion payment.

According to AhnLab, both groups also used identical malware filenames and execution arguments, the same privilege escalation tools, the same command-and-control servers, and the same SSH key fingerprint — a cryptographic identifier that functions like a unique digital signature. Both even deleted their malware the same way, renaming files to random four-character strings before wiping them.

AhnLab named the campaign “Operation Double Barrel,” but stopped short of definitively attributing both campaigns to the same actor, saying the overlaps could indicate collaboration, shared infrastructure, or access brokering. It classified the cases as having “a high likelihood of technical linkage” requiring continued investigation.

As part of their campaign, the attackers compromised 15 legitimate Korean websites across multiple industries and used them for watering-hole attacks, redirecting selected visitors of those compromised sites to specific infrastructure that triggered the software flaws and injected malicious code into legitimate Microsoft processes.

The intelligence agencies’ advisory warns both individuals and organizations to take defensive measures against the threat. In particular, the advisory alerts users that they may be infected simply by visiting a legitimate website that has been compromised, especially if they have outdated security software installed.

The attackers also ran spearphishing campaigns, with one targeting a Korean defense company with emails disguised as a survey about GaN semiconductors. AhnLab noted that the attackers appeared to have used AI to generate some of their lure pages.

The report identified multiple websites used for watering-hole attacks managed by the same Korean website development company. AhnLab assessed that the attackers likely compromised the hosting provider first and then expanded access to client sites through the development company’s management system, rather than hacking each one individually.

The findings add to a growing body of evidence that Pyongyang-backed hackers are deepening their entanglement with the ransomware ecosystem. In the past 18 months, different North Korean state-sponsored actors have been linked to the Play, Qilin, and Medusa ransomware operations by researchers at Palo Alto Networks, Microsoft, and Symantec respectively.

The increasing adoption of third-party ransomware by North Korean actors came under focus back in 2024, when the U.S. Department of Justice unsealed an indictment against Rim Jong Hyok, an alleged member of the government’s Andariel Unit, for his alleged role in ransomware attacks on U.S. hospitals and healthcare companies.

The Gunra connection may represent something different. In those earlier cases, North Korean operators joined established criminal franchises as affiliates. Here, the evidence suggests the relationship may run the other direction — with state hackers supplying tools, exploits, and access to a smaller, newer group.

Gunra emerged in April 2025, initially targeting five South Korean companies. The group built its ransomware on leaked Conti v2 source code before transitioning to a ransomware-as-a-service model in January of this year. Prior to the AhnLab report, industry researchers had tentatively linked Gunra to Eastern European operators based on its Conti heritage.

As of March 2026, the group had claimed at least 32 victims globally across healthcare, manufacturing, IT, and other sectors. As with many RaaS schemes, it operates a double-extortion model, stealing data before encrypting systems and threatening to publish it on a Tor-based leak site.

AhnLab warned that the risk extends beyond the organizations specifically targeted.

“The Korean financial security software currently being abused… is used not only in various enterprise environments but also on many personal PCs,” the company said.

“Because the vulnerabilities can be triggered simply when a user accesses a specific page, not only explicitly targeted organizations but also general user environments running vulnerable software may be exposed to risk.”

References in this story

  1. 국가사이버안보센터 www.ncsc.go.kr 국제 및 국가배후 해킹 조직 관련 사이버위협 예방·대응, 보안적합성·암호모듈 검증제도 등 정보수록
  2. North Korean hackers seen collaborating with Play ransomware group, researchers say therecord.media The incident signaled North Korea’s deeper involvement in the ransomware landscape after Jumpy Pisces actors were previously implicated by the Justice Department in attacks involving the Maui ransomware.
  3. Monthly news - July 2025 | Microsoft Community Hub techcommunity.microsoft.com Microsoft Defender XDRMonthly news - July 2025 Edition This is our monthly "What's new" blog post, summarizing product updates and various new assets we...
  4. North Korean state hackers seen using Medusa ransomware in attacks on US, Middle East therecord.media Cybersecurity researchers said they saw Medusa attacks launched by members of Lazarus — a well-known North Korean hacking operation housed within the country’s military — against a company in the Middle East and a…
  5. US indicts alleged North Korean state hacker for ransomware attacks on hospitals therecord.media Rim Jong Hyok was allegedly involved in ransomware attacks conducted in 2021 and 2022, including one on a hospital in Kansas.
  6. Andariel Latest News therecord.media Explore the latest trending news and updates on Andariel. Dive into insightful articles, analyses, and more to stay informed on Andariel.
  7. Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your business.
  8. Alex Martin (@AlexMartin) on X twitter.com UK Editor: @TheRecord_Media | Fellowship alumnus: @VirtualRoutes | @SkyNews | Agent: @NorthbankTalent
  9. Alexander Martin (@alexmartin.bsky.social) bsky.app Journalist covering cybersecurity and intelligence. UK Editor at The Record from Recorded Future News. Dad of two. 🏠 Sheffield 📧 [email protected] 📱 Signal: AlexanderMartin.79

Guides related to this story

← Back to all news