logo

[Joint Cybersecurity Advisory] Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware Group)

ID: 1155aae7-2374-5567-8eb2-dc19d4c828fc

STIX ID: report--1155aae7-2374-5567-8eb2-dc19d4c828fc

Feed Name: ASEC

Threat Score
90/100

Date Published: 2026-07-29

Date Updated: 2026-07-30

Author: ATCP

...
...

### Executive Summary The ASEC technical report analyzes "Operation Double Barrel," a sustained campaign (2025–first half 2026) that exploited vulnerabilities in Korean financial security software via watering‑hole and spear‑phishing vectors to install backdoors (Struggle/SIGNBT 3.0, Brandoor/COPPERHEDGE) and, in related cases, deploy Gunra ransomware; the report covers vulnerability analysis, malware behavior, IoCs (file hashes, domains, IPs), supply‑chain indicators, and technical linkages suggesting shared tools/infrastructure between a state‑sponsored actor and the ransomware group.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.