Thu 06 Aug 2026 / 09:44 ET
Kernel
Security 3 min read

Lazarus Gunra ransomware links flagged by South Korean agencies

AhnLab says Lazarus and Gunra used matching tools and servers against South Korean targets, pointing to possible cooperation or shared access.

Mara Chen-Doyle

By Mara Chen-Doyle / Staff Writer

Lazarus Gunra ransomware links flagged by South Korean agencies
img: The Record

South Korean security and intelligence agencies warned Thursday that the Lazarus Gunra ransomware connection may be more than coincidence, after AhnLab reported that North Korean state hackers and the Gunra extortion operation used overlapping tools, servers and attack methods against South Korean organizations.

AhnLab’s report says Lazarus, the North Korean hacking group widely tied to Pyongyang, and Gunra ran parallel campaigns from 2025 through the first half of 2026. The difference was the endgame: Lazarus installed espionage backdoors, while Gunra encrypted files, stole data and demanded payment.

The four South Korean agencies issued a joint advisory alongside the research, warning that people and companies can be compromised by visiting legitimate Korean websites that attackers have already poisoned. The risk is higher for users running outdated versions of Korean financial security software, which AhnLab says is used broadly on personal computers and in enterprise environments.

How did the Lazarus and Gunra attacks work?

AhnLab says both campaigns abused the same vulnerabilities in Korean financial security software products that are commonly needed for online banking and government services in South Korea. In watering-hole attacks, the hackers compromised legitimate sites, then redirected selected visitors to infrastructure that triggered the software flaws and injected malicious code into real Microsoft processes.

The company identified 15 compromised Korean websites across several industries. Several were managed by the same Korean website development company, leading AhnLab to assess that the attackers likely breached a hosting provider first and then used the developer’s management system to reach client sites, rather than breaking into each site one by one.

AhnLab also reported spearphishing activity, including emails aimed at a Korean defense company and disguised as a survey about gallium nitride, or GaN, semiconductors. The company said some lure pages appeared to have been generated with AI.

The overlap between the two campaigns is unusually specific. According to AhnLab, Lazarus and Gunra used the same malware file names and execution arguments, the same privilege-escalation tools, the same command-and-control servers and the same SSH key fingerprint. An SSH key fingerprint is a cryptographic identifier used to recognize a key, a bit like checking a machine-readable signature.

AhnLab said the operators also removed malware in the same way, renaming files to random four-character strings before deleting them. The company named the activity “Operation Double Barrel,” but did not say Gunra and Lazarus are definitely the same actor. It assessed a “high likelihood of technical linkage” and said the overlap could reflect cooperation, shared infrastructure or access brokering.

What is Gunra ransomware?

Gunra appeared in April 2025 and first targeted five South Korean companies, according to AhnLab. The group initially built its ransomware from leaked Conti v2 source code, then moved to a ransomware-as-a-service model in January 2026.

By March 2026, Gunra had claimed at least 32 victims worldwide in healthcare, manufacturing, IT and other sectors. Like many ransomware-as-a-service crews, it uses double extortion: steal files first, encrypt systems second, then threaten to publish the data on a Tor leak site.

The findings add a different wrinkle to North Korea’s known ransomware activity. Researchers at Palo Alto Networks, Microsoft and Symantec have previously linked North Korean state-backed actors to Play, Qilin and Medusa ransomware activity. In 2024, the U.S. Department of Justice also unsealed an indictment against Rim Jong Hyok, an alleged member of North Korea’s Andariel Unit, over alleged ransomware attacks on U.S. hospitals and healthcare companies.

AhnLab’s Gunra finding points in another direction: state-linked hackers may have supplied tools, exploit access or infrastructure to a newer ransomware group, rather than merely joining an established criminal affiliate program. That remains an assessment, not a settled attribution.

This story draws on original reporting from The Record.

More Security/

view all ↗