Infosecurity

North Korea’s Lazarus Group appears to be sharing cyberweapons with ransomware gangs, Seoul warns

Published

on

State hackers and cybercriminals may be working from the same playbook

For years, the line between state-sponsored espionage and common cybercrime has been blurring. Now, South Korean authorities say they have evidence that North Korea’s infamous Lazarus Group may be handing its tools directly to ransomware gangs.

A joint advisory from four South Korean security and intelligence agencies, released Thursday alongside a technical report from cybersecurity firm AhnLab, warns of a troubling overlap between Lazarus and a ransomware operation called Gunra. Both have been running parallel campaigns against South Korean targets since 2025. The only real difference? Their endgame.

Lazarus plants espionage backdoors. Gunra locks up files and demands payment.

Same flaws, same fingerprints, same servers

The report, which AhnLab dubbed “Operation Double Barrel,” details striking similarities between the two operations. Both groups exploited the same vulnerabilities in Korean financial security software — programs that are effectively mandatory for anyone using banking or government services in the country.

According to AhnLab, the two campaigns used:

  • Identical malware filenames and execution arguments
  • The same privilege escalation tools
  • Shared command-and-control servers
  • The same SSH key fingerprint — a cryptographic identifier akin to a unique digital signature

Both even deleted their malware the same way, renaming files to random four-character strings before wiping them clean.

That’s a lot of coincidences. AhnLab stopped short of definitively blaming both on the same actor, but classified the cases as having “a high likelihood of technical linkage.” The overlaps could indicate collaboration, shared infrastructure, or access brokering, the firm said.

Watering holes and weaponized websites

The scale of the operation is sobering. In 2026 alone, Lazarus hackers installed espionage backdoors in at least 72 organizations — including government agencies, cryptocurrency exchanges, and IT service providers. Gunra, meanwhile, used similar access to encrypt data and extort victims.

Part of the campaign involved compromising 15 legitimate Korean websites across multiple industries. The attackers turned these into watering holes, redirecting select visitors to infrastructure that triggered the software flaws and injected malicious code into legitimate Microsoft processes.

The advisory warns that users may be infected simply by visiting a legitimate website that has been compromised — especially if they’re running outdated security software.

The attackers also ran spearphishing campaigns. One targeted a Korean defense company with emails disguised as a survey about GaN semiconductors. AhnLab noted that some of the lure pages appeared to be generated with AI.

The hosting provider connection

Notably, multiple websites used for the watering-hole attacks were managed by the same Korean website development company. AhnLab assessed that the attackers likely compromised the hosting provider first, then expanded access to client sites through the development company’s management system — rather than hacking each site individually.

That’s a supply-chain approach, and it worked.

A growing entanglement with ransomware

The findings add to a growing body of evidence that Pyongyang-backed hackers are deepening their ties to the ransomware ecosystem. In the past 18 months, different North Korean state-sponsored actors have been linked to the Play, Qilin, and Medusa ransomware operations by researchers at Palo Alto Networks, Microsoft, and Symantec respectively.

That trend came into focus back in 2024, when the U.S. Department of Justice unsealed an indictment against Rim Jong Hyok, an alleged member of the government’s Andariel Unit, for his role in ransomware attacks on U.S. hospitals and healthcare companies.

But the Gunra connection may represent something different. In those earlier cases, North Korean operators joined established criminal franchises as affiliates. Here, the evidence suggests the relationship may run the other direction — with state hackers supplying tools, exploits, and access to a smaller, newer group.

Gunra emerged in April 2025, initially targeting five South Korean companies. The group built its ransomware on leaked Conti v2 source code before transitioning to a ransomware-as-a-service model in January of this year. Prior to the AhnLab report, industry researchers had tentatively linked Gunra to Eastern European operators based on its Conti heritage.

As of March 2026, Gunra had claimed at least 32 victims globally across healthcare, manufacturing, IT, and other sectors. Like many RaaS schemes, it operates a double-extortion model — stealing data before encrypting systems and threatening to publish it on a Tor-based leak site.

Who’s at risk?

AhnLab warned that the danger extends beyond the organizations specifically targeted.

“The Korean financial security software currently being abused… is used not only in various enterprise environments but also on many personal PCs,” the company said. “Because the vulnerabilities can be triggered simply when a user accesses a specific page, not only explicitly targeted organizations but also general user environments running vulnerable software may be exposed to risk.”

The advisory urges both individuals and organizations to update their security software and exercise caution when browsing. The threat isn’t abstract — it’s sitting on legitimate websites, waiting.

For more on how state-backed hackers operate, see our breakdown of North Korean cyber espionage tactics and ransomware-as-a-service trends.

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version