VYPR
advisoryPublished Jul 30, 2026· 1 source

North Korea's Lazarus Group Shares Tools With Ransomware Hackers, South Korean Agencies Warn

South Korean agencies and cybersecurity firms have uncovered evidence suggesting North Korea's Lazarus Group is collaborating with ransomware operations, sharing tools and infrastructure.

South Korean intelligence and cybersecurity agencies have issued a joint advisory warning that North Korea's notorious Lazarus Group appears to be sharing cyberattack tools and infrastructure with ransomware criminals. This revelation, detailed in a technical report by cybersecurity firm AhnLab, points to a deepening entanglement between state-sponsored North Korean hacking operations and financially motivated ransomware gangs targeting South Korean organizations.

The "Operation Double Barrel" campaign, as named by AhnLab, observed both the Lazarus Group and the Gunra ransomware scheme exploiting the same vulnerabilities in Korean financial security software. This software is a de facto requirement for accessing banking and government services in South Korea, making it a critical target. While Lazarus hackers focused on deploying espionage backdoors in at least 72 organizations this year, Gunra's objective was to encrypt files, steal data, and extort victims.

Compelling technical overlaps were identified, including identical malware filenames, identical execution arguments, the same privilege escalation tools, shared command-and-control servers, and even the same SSH key fingerprint. Both threat actors also employed the same method for deleting their malware, renaming files to random four-character strings before wiping them. AhnLab noted that these overlaps could indicate direct collaboration, shared infrastructure, or access brokering, classifying the cases as having a "high likelihood of technical linkage."

The attackers utilized compromised legitimate Korean websites for watering-hole attacks, redirecting unsuspecting visitors to malicious infrastructure that exploited software flaws and injected code into legitimate Microsoft processes. Spearphishing campaigns were also employed, with one instance targeting a Korean defense company using lures disguised as a survey about GaN semiconductors, potentially leveraging AI for lure page generation.

AhnLab's investigation revealed that the attackers likely compromised a website development company's management system, allowing them to gain access to multiple client websites simultaneously rather than hacking each one individually. This highlights a sophisticated approach to expanding their attack surface.

This finding aligns with a growing trend of North Korean state-sponsored actors becoming increasingly involved with the ransomware ecosystem. Previous research has linked North Korean actors to ransomware operations like Play, Qilin, and Medusa. However, the current case suggests a potentially different dynamic, where state hackers might be supplying tools and access to smaller, newer ransomware groups, rather than simply acting as affiliates.

The Gunra ransomware group, which emerged in April 2025 and initially targeted five South Korean companies, built its ransomware on leaked Conti v2 source code before transitioning to a ransomware-as-a-service model. As of March 2026, Gunra had claimed at least 32 victims globally across various sectors, employing a double-extortion model. The advisory emphasizes that the risk extends beyond directly targeted organizations, as the exploited financial security software is widely used in both enterprise and personal environments.

South Korean agencies are urging individuals and organizations to implement defensive measures, particularly against compromised websites and outdated security software. The interconnected nature of the threat, involving both state-sponsored espionage capabilities and ransomware operations, underscores the evolving sophistication and reach of North Korean cyber threats.

Synthesized by Vypr AI
North Korea's Lazarus Group Shares Tools With Ransomware Hackers, South Korean Agencies Warn · VYPR