North Korea’s Lazarus Group sharing tools with ransomware hackers, South Korean agencies warn
ID: 36fc6fca-a32b-56e1-84bb-00330588183a
STIX ID: report--36fc6fca-a32b-56e1-84bb-00330588183a
Feed Name: DataBreaches.Net
Threat Score
New research and a joint advisory indicate that North Korea’s Lazarus Group and the criminal Gunra ransomware operation ran parallel campaigns (2025–mid‑2026) against South Korean organizations by exploiting vulnerabilities in mandatory Korean financial security software; Lazarus implanted espionage backdoors in at least 72 organizations while Gunra used similar access to encrypt data and demand extortion payments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
