#DoubleBarrel

Incident/Operation

2026-07-30 • Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware Group)

Operation DoubleBarrel links a state-sponsored intrusion set and the Gunra ransomware group through overlapping attacks against South Korean citizens and organizations from 2025 through the first half of 2026. Both abused vulnerabilities in Korean financial-security software after watering-hole or spear-phishing delivery and shared elements of malware, credentials, tunneling infrastructure, and anti-forensic tradecraft; state-linked chains deployed Struggle and Brandoor backdoors, whereas Gunra attacks encrypted files and exfiltrated sensitive data. The actors are assessed to be separate but may have shared tools, infrastructure, techniques, or limited cooperation, and their relationship remains unconfirmed.

Tagged Reports

« Back