{"id":22982,"date":"2026-08-03T09:31:48","date_gmt":"2026-08-03T09:31:48","guid":{"rendered":"https:\/\/scannn.com\/north-koreas-lazarus-group-sharing-tools-with-ransomware-hackers-south-korean-agencies-warn\/"},"modified":"2026-08-03T09:31:48","modified_gmt":"2026-08-03T09:31:48","slug":"north-koreas-lazarus-group-sharing-tools-with-ransomware-hackers-south-korean-agencies-warn","status":"publish","type":"post","link":"https:\/\/scannn.com\/lv\/north-koreas-lazarus-group-sharing-tools-with-ransomware-hackers-south-korean-agencies-warn\/","title":{"rendered":"North Korea\u2019s Lazarus Group sharing tools with ransomware hackers, South Korean agencies warn"},"content":{"rendered":"\n<div id=\"\">\n<p class=\"paragraph\"> Cyberattack tools and infrastructure used by North Korea\u2019s Lazarus Group appear to have been shared with ransomware criminals targeting South Korean organizations, according to new research released Thursday alongside a <a href=\"https:\/\/www.ncsc.go.kr\/ko\/main\/PageLink.html?token=MDEyMzQ1Njc4OWFiY2RlZrBvBnCd4cC_Aqu-HrYk1bjY5ceD7POZ8O6txZr6KvMeZJhRV8iq7IvhLELla-3OseiDj4FZ8Z7DWmDkVDykCLeRYoxmm2gz7GApDO1zwli5\" target=\"_blank\" rel=\"noopener noreferrer\">joint advisory<\/a> by four South Korean security and intelligence agencies. <\/p>\n<p class=\"paragraph\"> The <a href=\"https:\/\/image.ahnlab.com\/atip\/content\/file\/20260730\/%5BAhnLab%5DOperation%20Double%20Barrel(ENG)(2026.07.30).pdf\" target=\"_blank\" rel=\"noopener noreferrer\">technical report<\/a> from cybersecurity firm AhnLab details how the state-sponsored North Korean group, widely tracked as Lazarus, and the Gunra ransomware scheme ran parallel campaigns against South Korean targets from 2025 through the first half of this year, differing only in their final objective. <\/p>\n<p class=\"paragraph\"> Both groups exploited the same vulnerabilities in Korean financial security software products that are effectively mandatory for anyone using Korean banking or government services. Where the Lazarus hackers have installed espionage backdoors in at least 72 organizations in 2026 alone \u2014 including government agencies, cryptocurrency exchanges, and IT service providers \u2014 Gunra has instead used its access to encrypt files, steal data and demand an extortion payment. <\/p>\n<p class=\"paragraph\"> According to AhnLab, both groups also used identical malware filenames and execution arguments, the same privilege escalation tools, the same command-and-control servers, and the same SSH key fingerprint \u2014 a cryptographic identifier that functions like a unique digital signature. Both even deleted their malware the same way, renaming files to random four-character strings before wiping them. <\/p>\n<p class=\"paragraph\"> AhnLab named the campaign \u201cOperation Double Barrel,\u201d but stopped short of definitively attributing both campaigns to the same actor, saying the overlaps could indicate collaboration, shared infrastructure, or access brokering. It classified the cases as having \u201ca high likelihood of technical linkage\u201d requiring continued investigation. <\/p>\n<p class=\"paragraph\"> As part of their campaign, the attackers compromised 15 legitimate Korean websites across multiple industries and used them for watering-hole attacks, redirecting selected visitors of those compromised sites to specific infrastructure that triggered the software flaws and injected malicious code into legitimate Microsoft processes. <\/p>\n<p class=\"paragraph\"> The intelligence agencies\u2019 advisory warns both individuals and organizations to take defensive measures against the threat. In particular, the advisory alerts users that they may be infected simply by visiting a legitimate website that has been compromised, especially if they have outdated security software installed. <\/p>\n<p class=\"paragraph\"> The attackers also ran spearphishing campaigns, with one targeting a Korean defense company with emails disguised as a survey about GaN semiconductors. AhnLab noted that the attackers appeared to have used AI to generate some of their lure pages. <\/p>\n<p class=\"paragraph\"> The report identified multiple websites used for watering-hole attacks managed by the same Korean website development company. AhnLab assessed that the attackers likely compromised the hosting provider first and then expanded access to client sites through the development company\u2019s management system, rather than hacking each one individually. <\/p>\n<p class=\"paragraph\"> The findings add to a growing body of evidence that Pyongyang-backed hackers are deepening their entanglement with the ransomware ecosystem. In the past 18 months, different North Korean state-sponsored actors have been linked to the Play, Qilin, and Medusa ransomware operations by researchers at<a href=\"https:\/\/therecord.media\/north-korean-hackers-collaborate-with-play-ransomware\" target=\"_blank\" rel=\"noopener noreferrer\"> Palo Alto Networks<\/a>,<a href=\"https:\/\/techcommunity.microsoft.com\/blog\/microsoftthreatprotectionblog\/monthly-news---july-2025\/4428862\" target=\"_blank\" rel=\"noopener noreferrer\"> Microsoft<\/a>, and<a href=\"https:\/\/therecord.media\/north-korean-hackers-using-medusa-ransomware\" target=\"_blank\" rel=\"noopener noreferrer\"> Symantec<\/a> respectively. <\/p>\n<p class=\"paragraph\"> The increasing adoption of third-party ransomware by North Korean actors came under focus back in 2024, when the U.S. Department of Justice<a href=\"https:\/\/therecord.media\/us-indicts-north-korean-hacker-ransomware\" target=\"_blank\" rel=\"noopener noreferrer\"> unsealed an indictment<\/a> against Rim Jong Hyok, an alleged member of the government\u2019s <a href=\"https:\/\/therecord.media\/tag\/andariel\" target=\"_blank\" rel=\"noopener noreferrer\">Andariel Unit<\/a>, for his alleged role in ransomware attacks on U.S. hospitals and healthcare companies. <\/p>\n<p class=\"paragraph\"> The Gunra connection may represent something different. In those earlier cases, North Korean operators joined established criminal franchises as affiliates. Here, the evidence suggests the relationship may run the other direction \u2014 with state hackers supplying tools, exploits, and access to a smaller, newer group. <\/p>\n<p class=\"paragraph\"> Gunra emerged in April 2025, initially targeting five South Korean companies. The group built its ransomware on leaked Conti v2 source code before transitioning to a ransomware-as-a-service model in January of this year. Prior to the AhnLab report, industry researchers had tentatively linked Gunra to Eastern European operators based on its Conti heritage. <\/p>\n<p class=\"paragraph\"> As of March 2026, the group had claimed at least 32 victims globally across healthcare, manufacturing, IT, and other sectors. As with many RaaS schemes, it operates a double-extortion model, stealing data before encrypting systems and threatening to publish it on a Tor-based leak site. <\/p>\n<p class=\"paragraph\"> AhnLab warned that the risk extends beyond the organizations specifically targeted.\u00a0 <\/p>\n<p class=\"paragraph\"> \u201cThe Korean financial security software currently being abused\u2026 is used not only in various enterprise environments but also on many personal PCs,\u201d the company said. <\/p>\n<p class=\"paragraph\"> \u201cBecause the vulnerabilities can be triggered simply when a user accesses a specific page, not only explicitly targeted organizations but also general user environments running vulnerable software may be exposed to risk.\u201d <\/p>\n<\/div>\n<p><a href=\"https:\/\/therecord.media\/north-korea-hackers-ransomware?utm_source=tldrinfosec\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cyberattack tools and infrastructure used by North Korea\u2019s Lazarus Group appear to have been shared with ransomware criminals targeting South Korean organizations, according to new research released Thursday alongside a joint advisory by four South Korean security and intelligence agencies. The technical report from cybersecurity firm AhnLab details how the state-sponsored North Korean group, widely [&hellip;]<\/p>\n","protected":false},"author":16,"featured_media":22983,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[143],"tags":[],"class_list":["post-22982","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai"],"_links":{"self":[{"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/posts\/22982","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/users\/16"}],"replies":[{"embeddable":true,"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/comments?post=22982"}],"version-history":[{"count":0,"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/posts\/22982\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/media\/22983"}],"wp:attachment":[{"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/media?parent=22982"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/categories?post=22982"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/tags?post=22982"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}