Operation Double Barrel: State-Sponsored Exploitation of Korean Financial Software

Operation Double Barrel: State-Sponsored Exploitation of Korean Financial Software

First seen 30 Jul 2026, 13:40 UTC Asec.AhnlabLazarus.Day 80% similarity 75.5

Article Content

Browse articles
ThreatCluster

From 2025 to mid-2026, a state-sponsored threat group exploited vulnerabilities in Korean financial security software, utilizing watering hole attacks and spear phishing to deploy backdoors named Struggle and Brandoor. AhnLab identified that attacks deploying Gunra ransomware shared initial access vulnerabilities and malware characteristics with this state actor, indicating possible collaboration or shared resources. Several compromised watering-hole sites were linked to a Korean web-development company, suggesting a supply-chain compromise. The advisory was issued by multiple South Korean agencies to alert citizens and businesses about these threats. The ongoing investigations are focused on understanding the full scope and implications of these attacks.

Key Points: • State-sponsored actors exploited vulnerabilities in Korean financial software from 2025 to mid-2026. • Attacks utilized watering holes and spear phishing to install backdoors Struggle and Brandoor. • AhnLab's findings indicate possible collaboration between the state actor and Gunra ransomware group.

ThreatCluster AI How this analysis works

Timeline

2025-01-01
Exploitation of vulnerabilities began
State-sponsored threat group started exploiting vulnerabilities in Korean financial security software.
Asec.Ahnlab
2026-01-15
Gunra ransomware attacks identified
AhnLab discovered ransomware attacks that shared characteristics with the state-sponsored group's activities.
Lazarus.Day
2026-07-29
Joint cybersecurity advisory issued
South Korean agencies released an advisory on cyberattacks targeting citizens and businesses by state hacking groups.
Asec.Ahnlab
2026-07-30
Operation Double Barrel report published
Lazarus.Day published a report detailing the relationship between the state actor and Gunra ransomware group.
Lazarus.Day

Community

Browse all →

Tracked Entities in This Story