ASEC identified a campaign dubbed 'Operation Double Barrel' linking a state-sponsored threat group and the Gunra ransomware group through shared exploitation of vulnerabilities in Korean financial security software, common malware families (SIGNBT 3.0 and COPPERHEDGE), overlapping SSH key fingerprints, and shared network infrastructure. The state-sponsored group used watering hole and spear-phishing attacks to deliver backdoors, while the Gunra group used the same initial access vectors to deploy ransomware. The shared infrastructure and techniques suggest limited collaboration or tool sharing between the two actors despite differing end objectives.
Gunra Ransomware
1 post
[Joint Cybersecurity Advisory] Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware Group)