South Korean authorities and AhnLab disclosed Operation Double Barrel, a campaign that targeted Korean citizens and businesses from 2025 through the first half of 2026 by exploiting vulnerabilities in Korean financial security software. The activity used watering hole and spear-phishing attacks to direct victims to malicious URLs, after which attackers deployed backdoors including Struggle (also tracked as SIGNBT 3.0) and Brandoor (COPPERHEDGE). Legitimate Korean websites in media, education, healthcare, and manufacturing were abused as part of the watering hole infrastructure, and investigators said the pattern also raised possible supply-chain concerns tied to a shared website development and management company.
The same software flaws were also used in separate intrusions that delivered Gunra ransomware, leading to file encryption and data exfiltration. A joint cybersecurity advisory issued by South Korea's National Intelligence Service, National Police Agency, Korea Internet & Security Agency, and Financial Security Institute said overlapping vulnerabilities, malware characteristics, SSH key fingerprints, and network infrastructure indicate possible limited collaboration or shared tooling between a state-sponsored threat actor and the Gunra ransomware group, although the relationship has not been confirmed definitively.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
A technical analysis report detailed six malware samples from the watering-hole campaign, grouped into three infection-chain types, including a COPPERHEDGE variant, loaders, downloaders, and concealed DLL payloads. The report described persistence, encryption, in-memory loading, anti-analysis techniques, and Korean C2 infrastructure, while noting that some intrusion-chain components remained unconfirmed.
ASEC identified separate incidents in which vulnerabilities in the same Korean financial security software were exploited to deploy Gunra ransomware, resulting in file encryption and data exfiltration. The report linked these incidents to the broader Operation Double Barrel findings through shared vulnerabilities, malware traits, SSH key fingerprints, and infrastructure.
AhnLab ASEC reported that a state-sponsored threat group targeted Korean citizens and businesses by exploiting vulnerabilities in Korean financial security software. The activity used watering hole and spear-phishing attacks and ran from 2025 through the first half of 2026.
Multiple South Korean institutions, including the National Intelligence Service, National Police Agency, Korea Internet & Security Agency, and Financial Security Institute, issued a joint cybersecurity advisory on Operation Double Barrel. The advisory addressed cyberattacks targeting Korean citizens and businesses and discussed the relationship between a state-sponsored threat actor and the Gunra ransomware group.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
bsky.app
Open sourcebsky.app
Open sourcemalware.news
Open sourceenki.co.kr
Open sourceasec.ahnlab.com
Open sourceasec.ahnlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.