Lazarus Tradecraft Spills Into South Korea’s Ransomware Scene
The bigger break is that one trust chain now serves both espionage and extortion. Korean banking and government plug-ins become the entry point, and the same tooling and infrastructure can be reused by state-linked operators and ransomware crews, so one incident no longer points to one motive.
South Korean agencies and AhnLab say Lazarus and Gunra campaigns ran in parallel against Korean targets from 2025 into this year. They used the same flaws in mandatory financial security software, the same command-and-control servers, the same SSH key fingerprint, and watering-hole attacks through 15 legitimate Korean websites; Lazarus has been tied to at least 72 espionage intrusions in 2026 alone, including government, crypto, and IT targets.
That makes the threat broader than a single actor story. If the same access path and infrastructure are shared across campaigns, defenders have to treat activity against Korean financial and government services as part of one ecosystem, not one name.