Threats · 46 days ago
The bigger break is that one trust chain now serves both espionage and extortion. Korean banking and government plug-ins become the entry point, and the same tooling and infrastructure can be reused by state-linked operators and ransomware crews, so one incident no longer points to one motive.
South Korean agencies and AhnLab say Lazarus and Gunra campaigns ran in parallel against Korean targets from 2025 into this year. They used the same flaws in mandatory financial security software, the same command-and-control servers, the same SSH key fingerprint, and watering-hole attacks through 15 legitimate Korean websites; Lazarus has been tied to at least 72 espionage intrusions in 2026 alone, including government, crypto, and IT targets.
That makes the threat broader than a single actor story. If the same access path and infrastructure are shared across campaigns, defenders have to treat activity against Korean financial and government services as part of one ecosystem, not one name.
2 sources covering this story
The Record from Recorded Future
North Korea’s Lazarus Group sharing tools with ransomware hackers, South Korean agencies warn
Cyberattack tools and infrastructure used by North Korea’s Lazarus Group appear to have been shared with ransomware criminals targeting South Korean organizations — further evidence of deepening entanglement between Pyongyang-backed hackers and the ransomware ecosystem.
North Korea's elite hackers turned on their own government — and got caught
For years, North Korea's state-trained hackers have been one of the world's most prolific robbers of banks - stealing huge sums of money from foreign financial instituions, draining cryptocurrency exchanges of billions, and funnelling the proceeds into the country's weapons programme.
Part of the PlainSec briefing for 2026-07-30