#DoubleBarrel
Incident/Operation
Operation DoubleBarrel links a state-sponsored intrusion set and the Gunra ransomware group through overlapping attacks against South Korean citizens and organizations from 2025 through the first half of 2026. Both abused vulnerabilities in Korean financial-security software after watering-hole or spear-phishing delivery and shared elements of malware, credentials, tunneling infrastructure, and anti-forensic tradecraft; state-linked chains deployed Struggle and Brandoor backdoors, whereas Gunra attacks encrypted files and exfiltrated sensitive data. The actors are assessed to be separate but may have shared tools, infrastructure, techniques, or limited cooperation, and their relationship remains unconfirmed.
-
2
Tagged Reports
-
1
Unique Authors
-
1
Active Days