North Korea’s Lazarus Group sharing tools with ransomware hackers, South Korean agencies warn
Cyberattack tools and infrastructure used by North Korea’s Lazarus Group appear to have been shared with ransomware criminals targeting South Korean organizations — further evidence of deepening entanglement between Pyongyang-backed hackers and the ransomware ecosystem.
Cyberattack tools and infrastructure used by North Korea’s Lazarus Group appear to have been shared with ransomware criminals targeting South Korean organizations, according to new research released Thursday alongside a joint advisory by four South Korean security and intelligence agencies.
The technical report from cybersecurity firm AhnLab details how the state-sponsored North Korean group, widely tracked as Lazarus, and the Gunra ransomware scheme ran parallel campaigns against South Korean targets from 2025 through the first half of this year, differing only in their final objective.
Both groups exploited the same vulnerabilities in Korean financial security software products that are effectively mandatory for anyone using Korean banking or government services. Where the Lazarus hackers have installed espionage backdoors in at least 72 organizations in 2026 alone — including government agencies, cryptocurrency exchanges, and IT service providers — Gunra has instead used its access to encrypt files, steal data and demand an extortion payment.
Source: https://therecord.media/north-korea-hackers-ransomware
Related breach coverage
- South Korea Warns of State-Backed Watering Hole Attacks2026-07-31
South Korea warned that nation-state actors are using phishing and compromised websites to silently infect citizens and businesses. South Korea agencies (The National Intelligence Service, the National Police Agency, the Korea Internet & Security Agency, and the Financial Security Institute) jointly published an advisory warning that a state-backed hacking group is actively targeting South Korean […]
- North Korean hackers behind major open-source supply chain attacks, Amazon says2026-07-30
A North Korea-linked hacker group was behind several high-profile compromises of open-source software libraries used by developers worldwide, researchers have found.
- US Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra Servers2026-07-24
US agencies warn Russian group Laundry Bear is exploiting a patched Zimbra flaw to steal email accounts from organizations running unpatched servers. The Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Federal Bureau of Investigation (FBI) and other U.S. government and international partners published a joint advisory to warn that the Russia-linked APT […]
- New Crypter-as-a-Service Cruciferra Fuels Stealthy Malware Attacks Worldwide2026-07-28
Proofpoint uncovered Cruciferra, a crypter-as-a-service that helps hackers evade antivirus and deliver malware in multiple campaigns. Proofpoint’s research team traced a wave of income-tax-themed lures targeting Indian taxpayers, tax professionals, and corporate finance teams back to a crypter service called Cruciferra, and the tool turns out to be shared infrastructure used across multiple unrelated criminal […]