AhnLab reports that a state-sponsored group abused vulnerabilities in Korean financial security software from 2025 through the first half of 2026 to deliver backdoors via watering hole and spear-phishing attacks, while many compromised Korean websites were used as infection points. The analysis also finds overlap with Gunra ransomware incidents and names the campaign Operation Double Barrel, citing shared vulnerabilities, malware, SSH key fingerprints, and network infrastructure. #OperationDoubleBarrel #Gunra #Struggle #Brandoor #SIGNBT3.0 #COPPERHEDGE
Keypoints
- The report is part of a joint cybersecurity advisory by NIS, NPA, KISA, and FSI on attacks targeting Korean citizens and businesses.
- A state-sponsored threat group continuously distributed malware from 2025 through H1 2026 by exploiting vulnerabilities in Korean financial security software.
- Attackers used watering hole and spear-phishing tactics to lure victims to malicious URLs and then deployed backdoor malware.
- Legitimate Korean websites in media, education, healthcare, and manufacturing were abused in watering hole campaigns.
- The backdoors identified in the campaign include Struggle (SIGNBT 3.0) and Brandoor (COPPERHEDGE), along with additional tools for privilege escalation and payload delivery.
- Separate attack cases involving Gunra ransomware reused the same financial security software vulnerabilities and showed overlaps in malware, SSH key fingerprints, and network infrastructure.
- ASEC named the campaign Operation Double Barrel and raised the possibility of shared techniques, tools, infrastructure, or limited collaboration between the two threat actors.
MITRE Techniques
- [T1189 ] Drive-by Compromise – Victims were directed to malicious webpages placed on legitimate sites to trigger infection through browsing (‘legitimate Korean websites … were confirmed to have been abused in watering hole attacks’).
- [T1566.002 ] Spearphishing Link – The attackers induced targets to access malicious URLs through spear-phishing (‘induced targets to access malicious URLs through various methods, including … spear-phishing attacks’).
- [T1190 ] Exploit Public-Facing Application – The group exploited vulnerabilities in financial security software to gain initial access (‘exploiting vulnerabilities in Korean financial security software’).
- [T1105 ] Ingress Tool Transfer – Staged payloads and malware were delivered after exploitation (‘staged payload delivery process’).
- [T1059 ] Command and Scripting Interpreter – The report references downloaded tools and malware execution workflows commonly used for post-exploitation control (‘ultimately install backdoor malware’).
- [T1003 ] OS Credential Dumping – The analysis notes credential-related commonalities between campaigns, indicating abuse of credentials (‘commonalities … credentials’).
- [T1021.004 ] Remote Services: SSH – Shared SSH key fingerprints were identified as technical links (‘SSH key fingerprints’).
- [T1071.001 ] Application Layer Protocol: Web Protocols – Network infrastructure included download and reverse tunneling addresses used over web-connected infrastructure (‘network infrastructure such as download and reverse tunneling addresses’).
- [T1078 ] Valid Accounts – The report discusses abuse of legitimate access and credentials as part of the attack comparisons (‘commonalities … credentials’).
Indicators of Compromise
- [File names ] referenced malware and report artifacts – Operation Double Barrel, AhnLab]Operation Double Barrel(KOR)(2026.07.30).pdf, [AhnLab]Operation Double Barrel(ENG)(2026.07.30).pdf
- [Malware names ] backdoors and related malware – Struggle, Brandoor, Gunra
- [Malware family aliases ] alternate names used in the report – SIGNBT 3.0, COPPERHEDGE
- [URL/domain indicators ] malicious access and infrastructure are mentioned, but specific values are in the attached report – malicious URLs, related domains, and other URLs
- [IP addresses ] network infrastructure is referenced in the report summary, with specific addresses listed in the attached appendix – download and reverse tunneling addresses, and other IPs
- [Hashes ] file hashes are included in the attached IoC section, though values are not shown in the excerpt – MD5 hashes, and other hashes
- [SSH key fingerprints ] technical link indicators shared across campaigns – SSH key fingerprints, and other fingerprints
Read more: https://asec.ahnlab.com/en/94696/