Operation Double Barrel is a threat campaign tracked by ThreatCluster, appearing in 1 threat cluster built from 3 intelligence report mentions.
Operation Double Barrel is a threat campaign tracked across 1 threat cluster and 3 intelligence report mentions on ThreatCluster. First observed July 29, 2026; most recent activity July 30, 2026.
From 2025 to mid-2026, a state-sponsored threat group exploited vulnerabilities in Korean financial security software, utilizing watering hole attacks and spear phishing to deploy backdoors named Struggle and Brandoor.…
Operation Double Barrel is a threat campaign tracked by ThreatCluster, appearing in 1 threat cluster built from 3 intelligence report mentions.
The most recent intelligence report mentioning Operation Double Barrel on ThreatCluster is dated July 30, 2026. Activity was first observed July 29, 2026, giving a tracked span from then to July 30, 2026.
Across ThreatCluster reporting, Operation Double Barrel most frequently co-occurs with Lazarus, Malware, Phishing, Ransomware, Supply Chain Attack, among 12 tracked related entities.
The most significant recent cluster is “Operation Double Barrel: State-Sponsored Exploitation of Korean Financial Software” (3 articles · Updated July 30, 2026). Operation Double Barrel appears across 1 threat cluster in total, listed above with sources.
Operation Double Barrel appears in 3 intelligence report mentions across 1 deduplicated threat cluster, aggregated from 17,000+ monitored sources.