Hacked Korean websites pushed spy backdoors and Gunra ransomware

Hackers broke into a string of legitimate Korean websites, including media outlets, schools, hospitals and manufacturers, and used them to push spying backdoors onto visitors by abusing flaws in the security software Koreans install to bank online. In some of the intrusions the same flaws ended with Gunra ransomware encrypting files and stealing internal data instead.

The finding comes from AhnLab Security intelligence Center (ASEC), whose technical report accompanies a joint advisory issued by South Korea's National Intelligence Service, National Police Agency, Korea Internet and Security Agency (KISA) and the Financial Security Institute on attacks targeting Korean citizens and businesses. ASEC named the campaign Operation Double Barrel.

What happened

ASEC says a state-sponsored group distributed malware continuously from 2025 through the first half of 2026 by exploiting vulnerabilities in two Korean financial security products, the client agents and plugins that banks and institutional portals require users to install. Targets were steered to malicious URLs through watering hole attacks (compromising a site the target already visits and waiting for them) and spear-phishing, then exploited and served a staged payload chain that ended in a backdoor.

The two backdoors ASEC analyzed are Struggle, which it identifies as SIGNBT 3.0, and Brandoor, which it identifies as COPPERHEDGE. Both families have been documented in earlier North Korean intrusion sets, though ASEC's report itself stops short of naming the group behind these attacks. Post-exploitation leaned on off-the-shelf tooling rather than bespoke implants: Impacket and PsExec for lateral movement, Plink and Socat for tunneling, TightVNC, WinSCP and FileZilla for access and file transfer, Certipy and PetitPotam for Active Directory certificate abuse, UACMe for bypassing User Account Control, plus webshells.

Where Gunra comes in

Separately, ASEC found intrusions that started the same way, through the same flaw in one of the financial security products and even the same watering hole page, but ended with Gunra ransomware. Beyond the shared entry point, the two sets of attacks shared installed malware, SSH key fingerprints, download and reverse tunneling infrastructure, and anti-forensic techniques.

ASEC's conclusion is deliberately narrow. The espionage group and the ransomware crew look like separate actors with different end goals, but they may have shared techniques, tools and infrastructure, or cooperated in a limited way during the attacks. ASEC states plainly that it cannot determine the relationship from the evidence gathered so far, and picked the "double barrel" name for two attack flows aimed in the same direction. Such overlaps are not unprecedented: US and allied agencies previously tied North Korea's Andariel group to Play ransomware deployments.

ASEC also raises a supply chain question. Several of the abused watering hole sites were built and maintained by the same Korean web development and management company, which would hand one intrusion reach into many otherwise unrelated organizations. Watering holes against Korean financial client software are a recurring pattern here: Lazarus ran the same playbook against MagicLine in Operation Dream Magic, and South Korea remains one of the most heavily targeted countries for this tradecraft.

What you should do

Organizations running Korean financial security clients should update them to current versions and treat older installs on employee endpoints as exposed, since that software often sits outside normal patch inventories. Hunt for the tooling above, in particular Plink or Socat reverse tunnels leaving the network, Certipy and PetitPotam activity against certificate services, and unexpected SSH authorized keys. ASEC published Korean and English versions of the full report, with file hashes and network indicators in the report and its AhnLab TIP feed. Read the original analysis for the detail.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Detection coverage

Read the full analysis on IntelFusions