Researchers from the cybersecurity company AhnLab have found evidence that the North Korean advanced persistent threat group Lazarus may be sharing tools and access to compromised systems with the ransomware gang Gunra, which has focused its attacks on organizations in South Korea.
According to the report, both groups exploited the same vulnerabilities in a widely used security software to access South Korean banks and public services. However, their objectives were different: while Lazarus used these accesses for espionage activities, Gunra used them to encrypt files, steal information, and demand ransoms.
The researchers found numerous technical similarities between both campaigns, such as the use of the…







