[Joint Cybersecurity Advisory] Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware Group)
ID: 1155aae7-2374-5567-8eb2-dc19d4c828fc
STIX ID: report--1155aae7-2374-5567-8eb2-dc19d4c828fc
Feed Name: ASEC
### Executive Summary The ASEC technical report analyzes "Operation Double Barrel," a sustained campaign (2025–first half 2026) that exploited vulnerabilities in Korean financial security software via watering‑hole and spear‑phishing vectors to install backdoors (Struggle/SIGNBT 3.0, Brandoor/COPPERHEDGE) and, in related cases, deploy Gunra ransomware; the report covers vulnerability analysis, malware behavior, IoCs (file hashes, domains, IPs), supply‑chain indicators, and technical linkages suggesting shared tools/infrastructure between a state‑sponsored actor and the ransomware group.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
