Lazarus isn’t just stealing crypto anymore—it’s arming ransomware gangs | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


Researchers from the cybersecurity company AhnLab have found evidence that the North Korean advanced persistent threat group Lazarus may be sharing tools and access to compromised systems with the ransomware gang Gunra, which has focused its attacks on organizations in South Korea.

According to the report, both groups exploited the same vulnerabilities in a widely used security software to access South Korean banks and public services. However, their objectives were different: while Lazarus used these accesses for espionage activities, Gunra used them to encrypt files, steal information, and demand ransoms.

The researchers found numerous technical similarities between both campaigns, such as the use of the same command and control servers, tools to elevate privileges, or even the same digital fingerprint of an SSH key.

However, AhnLab notes that these similarities could be due to collaboration, the use of shared infrastructure, or the buying and selling of accesses among cybercriminals, not necessarily that the two groups are the same.

On the other hand, the attackers compromised at least 15 legitimate websites to infect their visitors through attacks known as watering holes, where a user can be affected simply by accessing a trusted website if they have vulnerable software installed.

The cybersecurity firm warns that the risk is not limited to the attacked organizations.

The South Korean financial security software currently being exploited is used not only in numerous business environments but also on many personal computers,” the company explained.

Additionally, AhnLab reminds that “vulnerabilities can be triggered simply when a user accesses a specific page,” so both companies and individuals using vulnerable versions of the software may be exposed.

Who’s who

Lazarus Group is the name used by the cybersecurity community to identify one of the most active and sophisticated advanced persistent threat (APT) groups in the world. It is believed to operate under the control of the Reconnaissance General Bureau (RGB), North Korea’s main intelligence service.

Its activity began to be detected around 2009, although it gained international notoriety in 2014 with the attack on Sony Pictures Entertainment, carried out in retaliation for the release of the movie The Interview, a satire about Kim Jong-un.

Since then, the group has evolved from sabotage and espionage operations to campaigns aimed at obtaining funding for the North Korean regime through thefts from banks, cryptocurrency platforms, and other digital assets.

As for Gunra, it is a much more recent ransomware group. Its public appearance occurred in April 2025, when it began attacking South Korean companies.

Researchers who have tracked it indicate that this extortion group developed its malicious tool from the leaked source code of Conti v2, one of the most important ransomware in recent years. Subsequently, it evolved into a Ransomware-as-a-Service (RaaS) model, launched in January of this year.

Researchers from the cybersecurity company AhnLab have found evidence that the North Korean advanced persistent threat group Lazarus may be sharing tools and access to compromised systems with the ransomware gang Gunra, which has focused its attacks on organizations in South Korea.

According to the report, both groups exploited the same vulnerabilities in a widely used security software to access South Korean banks and public services. However, their objectives were different: while Lazarus used these accesses for espionage activities, Gunra used them to encrypt files, steal information, and demand ransoms.

The researchers found numerous technical similarities between both campaigns, such as the use of the same command and control servers, tools to elevate privileges, or even the same digital fingerprint of an SSH key.

However, AhnLab notes that these similarities could be due to collaboration, the use of shared infrastructure, or the buying and selling of accesses among cybercriminals, not necessarily that the two groups are the same.

On the other hand, the attackers compromised at least 15 legitimate websites to infect their visitors through attacks known as watering holes, where a user can be affected simply by accessing a trusted website if they have vulnerable software installed.

The cybersecurity firm warns that the risk is not limited to the attacked organizations.

The South Korean financial security software currently being exploited is used not only in numerous business environments but also on many personal computers,” the company explained.

Additionally, AhnLab reminds that “vulnerabilities can be triggered simply when a user accesses a specific page,” so both companies and individuals using vulnerable versions of the software may be exposed.

Who’s who

Lazarus Group is the name used by the cybersecurity community to identify one of the most active and sophisticated advanced persistent threat (APT) groups in the world. It is believed to operate under the control of the Reconnaissance General Bureau (RGB), North Korea’s main intelligence service.

Its activity began to be detected around 2009, although it gained international notoriety in 2014 with the attack on Sony Pictures Entertainment, carried out in retaliation for the release of the movie The Interview, a satire about Kim Jong-un.

Since then, the group has evolved from sabotage and espionage operations to campaigns aimed at obtaining funding for the North Korean regime through thefts from banks, cryptocurrency platforms, and other digital assets.

As for Gunra, it is a much more recent ransomware group. Its public appearance occurred in April 2025, when it began attacking South Korean companies.

Researchers who have tracked it indicate that this extortion group developed its malicious tool from the leaked source code of Conti v2, one of the most important ransomware in recent years. Subsequently, it evolved into a Ransomware-as-a-Service (RaaS) model, launched in January of this year.


——————————————————-


Click Here For The Original Source.

National Cyber Security

FREE
VIEW