South Korean agencies warn Lazarus and Gunra ransomware share tools and infrastructure in attacks on Korean organizations

South Korean agencies say North Korea’s Lazarus hackers and the Gunra ransomware operation used overlapping tools and infrastructure to attack South Korean organizations. AhnLab’s 'Operation Double Barrel' report says the campaigns exploited flaws in Korean financial security software used for banking and government services, compromised 15 legitimate Korean websites for watering-hole attacks, and also used spearphishing; victims included government agencies, cryptocurrency exchanges, IT service providers, and a defense company.
Why it matters: This matters because people and organizations could be infected just by visiting a compromised legitimate site if they have outdated required security software installed. South Korean users and defenders should prioritize patching related software, review web and email defenses, and investigate for the shared malware, command-and-control infrastructure, and SSH key overlap described in the advisory.

Sources

US and South Korea warn of Gunra ransomware targeting govt agencies
Sergiu Gatlan 2026.08.11 78% relevant
This advances the same Gunra ransomware campaign by adding a joint U.S.-South Korea advisory that details Gunra’s targeting of government and critical infrastructure worldwide, its use of Fortinet CVEs CVE-2024-55591 and CVE-2025-24472, Linux expansion, and its formal RaaS affiliate program under the Golden Community alias.
FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure
2026.08.10 78% relevant
This advances the same Gunra campaign by adding a joint FBI–South Korea advisory, naming active exploitation of Fortinet flaws CVE-2024-55591 and CVE-2025-24472, broader targeting of healthcare, finance, and government, ransom demands over $10 million, and the group's shift to a ransomware-as-a-service model under aliases including Golden Community.
North Korea’s Lazarus Group sharing tools with ransomware hackers, South Korean agencies warn
2026.07.30 100% relevant
This article establishes a distinct story by introducing the South Korean joint advisory and AhnLab's Operation Double Barrel findings that specifically link Lazarus tradecraft and infrastructure to the Gunra ransomware campaign targeting South Korean organizations.
← Back to all stories