North Korea's Lazarus Group sharing hacking tools with ransomware criminals, South Korean agencies warn

Cyberattack tools and infrastructure used by North Korea's Lazarus Group have been shared with ransomware criminals targeting South Korean organizations, according to research released Thursday by cybersecurity firm AhnLab alongside a joint advisory from four South Korean security and intelligence agencies.
The technical report details how Lazarus and the Gunra ransomware scheme ran parallel campaigns against South Korean targets from 2025 through mid-2026, using identical malware filenames, privilege escalation tools, command-and-control servers and SSH key fingerprints. Lazarus installed espionage backdoors in at least 72 organizations in 2026 alone, while Gunra used its access to encrypt files and demand ransom payments. Both groups exploited the same vulnerabilities in Korean financial security software products that are effectively mandatory for banking and government services.
AhnLab classified the overlaps as having "a high likelihood of technical linkage" but stopped short of definitively attributing both campaigns to the same actor, saying the evidence could indicate collaboration, shared infrastructure or access brokering, The Record reports.