Operation Double Barrel: State-Sponsored Exploitation of Korean Financial Software
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
From 2025 to mid-2026, a state-sponsored threat group exploited vulnerabilities in Korean financial security software, utilizing watering hole attacks and spear phishing to deploy backdoors named Struggle and Brandoor. AhnLab identified that attacks deploying Gunra ransomware shared initial access vulnerabilities and malware characteristics with this state actor, indicating possible collaboration or shared resources. Several compromised watering-hole sites were linked to a Korean web-development company, suggesting a supply-chain compromise. The advisory was issued by multiple South Korean agencies to alert citizens and businesses about these threats. The ongoing investigations are focused on understanding the full scope and implications of these attacks.
Key Points: • State-sponsored actors exploited vulnerabilities in Korean financial software from 2025 to mid-2026. • Attacks utilized watering holes and spear phishing to install backdoors Struggle and Brandoor. • AhnLab's findings indicate possible collaboration between the state actor and Gunra ransomware group.