Skip to content
Operation Double Barrel (The Relationship Between a State

Operation Double Barrel (The Relationship Between a State

Lazarus.Day July 30, 2026

A state- threat group exploited vulnerabilities in Korean financial security software from 2025 through the first half of 2026, using watering holes and spear phishing to install Struggle (SIGNBT 3.0) and Brandoor (COPPERHEDGE) backdoors. AhnLab found that separate attacks deploying Gunra ransomware shared initial-access vulnerabilities, malware characteristics, SSH key fingerprints, and network infrastructure with this activity. The overlaps suggest limited collaboration or shared resources between the actors, although AhnLab could not establish their relationship conclusively. Several compromised watering-hole sites were connected to one Korean web-development and management company, raising a possible supply-chain angle.

Extracted Entities