Cyberwarfare / Nation-State Attacks
    ,
    Fraud Management & Cybercrime
    ,
    Ransomware

    AhnLab Found Shared Malware, SSH Keys and Infrastructure Across Two Campaigns

    Tiffany Wang
    July 31, 2026    

    North Korea’s APT Capabilities Are No Longer State-Exclusive
    The Ryugyong Hotel in Pyongyang, North Korea, in a photo dated May 22, 2018. (Image: Torsten Pursche/Shutterstock)

    North Korean government’s hacking capabilities are spilling into private hands and, in one case, may have even been used by Pyongyang veteran hackers-turned-cybercriminals to attack the state itself.

    See Also: Experts Offer Insights from Theoretical to the Realities of AI-enabled Cybercrime

    The Gunra ransomware gang appears to share similarities in tactics, techniques and procedures with regime hackers, South Korean cybersecurity firm AhnLab said of a campaign it dubs “Operation Double Barrel.”

    On the flip side, passing around hacking tricks may have come back to bite the government itself. Discharged veterans from a cyber operations unit in North Korea’s military intelligence agency recruited hacking talents from local universities and built a cryptocurrency-laundering network by stealing from the country’s major banks, South Korean online newspaper Daily NK reported last week.

    North Korean hackers tracked as Lazarus Group and Gunra each exploited the same initial-access vulnerabilities in South Korean financial security software, deployed the same malware, and shared SSH key fingerprints and network infrastructure, including download and reverse-tunneling addresses, AhnLab said in a supplemental report to a joint advisory from the South Korean government and intelligence authorities Thursday.

    “These commonalities suggest that although the state-sponsored threat group and the Gunra ransomware group appear to be separate threat actors with different ultimate objectives, they may have shared certain techniques, tools and infrastructure or collaborated to a limited extent during the attacks,” AhnLab said.

    Lazarus compromised legitimate South Korean websites from various industries – including media, educational, healthcare and manufacturing – that were frequently visited by its targets. It also sent phishing emails disguised as resumes or surveys that contained malicious links, AhnLab said.

    Once the victim accessed a compromised site, the actor exploited security flaws in older versions of “Korean financial security software installed when using financial and institutional services” and eventually planted backdoor malware, AhnLab said.

    The ransomware group also exploited the same software, “but Gunra ransomware was ultimately installed to encrypt files and exfiltrate sensitive organizational information,” AhnLab said. Gunra used double-extortion and a ransomware-as-a-service model to pressure its victims into paying.

    The parallel campaign both align with North Korea state interests. But a scandal shook Pyongyang’s elite and military circles, Daily NK said, when a criminal ring of former government hackers and their college-level employees stole “substantial wealth” from state trade funds using skills hackers learned in the military and at Kim Chaek University of Technology and Pyongyang University of Science.

    The North Korean cybercriminal group broke into the internal networks and foreign payment systems of Chosun Central Bank and the Foreign Trade Bank using Chinese-made wireless equipment, Daily NK’s source in Pyongyang said. The launderers split the funds into tiny amounts and trickled the money into cryptocurrency wallets abroad, where Chinese brokers converted it into cash and delivered U.S. dollars and Chinese yuan to the North Koreans at the border.

    Despite the group’s efforts to evade detection, security officials noticed small discrepancies in accounting and suspicious overseas IP access and traced encrypted cryptocurrency transaction traffic to a house in Pyongyang, where they arrested the ringleaders and IT personnel in a raid on July 12.

    “They used the skills the state trained them with to defend the country, and instead robbed the country’s coffers,” one official said, according to Daily NK’s source. “This goes beyond ordinary guilt-by-association penalties. It will be hard for the entire family line to survive.”

    Share.

    Comments are closed.