Cyberattack tools and infrastructure used by North Korea’s Lazarus Group appear to have been shared with ransomware criminals targeting South Korean organizations, according to new research released Thursday alongside a joint advisory by four South Korean security and intelligence agencies. Both groups exploited the same vulnerabilities in Korean financial security software products that are effectively mandatory for anyone using Korean banking or government services. In those earlier cases, North Korean operators joined established criminal franchises as affiliates. Gunra emerged in April 2025, initially targeting five South Korean companies. “The Korean financial security software currently being abused… is used not only in various enterprise environments but also on many personal PCs,” the company said.