Lazarus-Linked Lures Hit Korea via Surveys & Sites

The Record · High sophistication
Last updated July 30, 2026

South Korean agencies and AhnLab warn that tools tied to North Korea’s Lazarus Group appear to be shared with the Gunra ransomware operation targeting South Korean organizations. The campaign used compromised legitimate websites (watering-hole attacks) and spearphishing emails, including messages disguised as a semiconductor survey, to trigger flaws in widely used Korean financial security software and deliver malicious code.

How the campaign worked

According to AhnLab and South Korean agencies, tools associated with the Lazarus Group appear to have been shared with the Gunra ransomware operation, with both running parallel campaigns against South Korean targets between 2025 and the first half of 2026. Their goals differed: espionage in one case, ransomware extortion in the other, but the delivery methods overlapped.

One track used spearphishing. A Korean defense company received emails disguised as a survey about GaN semiconductors, pushing recipients toward a lure page. AhnLab noted that some of these lure pages appeared to have been generated with AI, making them harder to distinguish from a genuine survey request.

The second track relied on watering-hole attacks. Attackers compromised 15 legitimate Korean websites across multiple industries and used them to redirect selected visitors to infrastructure that triggered flaws in widely used Korean financial security software, injecting malicious code into legitimate Microsoft processes. AhnLab assessed that attackers likely compromised a hosting provider or development company's management system to expand this access across many client sites at once.

Why it succeeded

The Korean financial security software involved is described as effectively mandatory for banking and government services, meaning a large population of users had it installed and were exposed to the same vulnerabilities. Because the flaws could be triggered simply by loading a specific page, infection did not require the victim to open a file or approve any prompt, and outdated security software increased the risk further. The survey pretext also exploited a routine, low-suspicion business activity, an industry or academic survey request, to reach a defense-adjacent audience.

What to watch for

  • Unexpected survey requests tied to sensitive or specialized technical topics, particularly those sent to defense, engineering, or R&D staff
  • Pressure to click an external link to complete a questionnaire or lure page
  • Generic or oddly worded lure content, which may indicate AI-generated material
  • Unexpected browser redirects when visiting familiar, trusted websites
  • Unusual pop-ups, prompts, or downloads appearing on normally routine sites

Building resistance

Organizations should keep endpoint and financial security software fully patched, since some infections in this campaign occurred simply from browsing to a compromised legitimate site. Employees, especially in finance, defense, engineering, and IT roles, should be encouraged to verify unexpected survey or research requests before clicking any link. IT and security teams should treat unexpected redirects on known sites as a reportable event rather than a minor annoyance, since watering-hole infrastructure can affect general user environments running vulnerable software, not just explicitly targeted organizations.

Key findings

  • AhnLab reported Lazarus and Gunra ran parallel campaigns against South Korean targets (2025 through first half of 2026), with different end goals (espionage vs. ransomware extortion).
  • Attackers abused vulnerabilities in Korean financial security software described as effectively mandatory for Korean banking/government services.
  • The campaign included watering-hole attacks using compromised legitimate Korean websites to redirect visitors and trigger software flaws.
  • A spearphishing campaign targeted a Korean defense company using emails disguised as a survey about GaN semiconductors.
  • Advisory warns infection may occur just by visiting a compromised legitimate site, especially with outdated security software.
  • AhnLab stated attackers likely compromised a hosting provider/development company management system to expand access to many client sites.

Who’s being targeted

  • Commonly targeted roles: All employees, Engineering/R&D, Defense programs, Finance teams who use banking-related security software, IT/Security teams responsible for patching and endpoint controls.
  • Affected industries: Government agencies, Cryptocurrency exchanges, IT service providers, Defense contractors, Healthcare, Manufacturing.
  • Attack channels: email, website.
  • Impersonated: Survey organizer / semiconductor research group (unspecified), A legitimate (but compromised) Korean website.

Red flags to watch for

  • Unexpected survey request tied to sensitive defense-adjacent topic
  • Pressure to click an external link to a survey page
  • Lure content appears machine-generated or unusually generic
  • Browser redirects to a different site unexpectedly
  • Infection can occur simply from visiting a page, especially with outdated security software
  • Legitimate site behavior changes (pop-ups, unusual prompts, unexpected downloads)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the attackers target a Korean defense company?

They sent spearphishing emails disguised as a survey about GaN semiconductors, aiming to get recipients to click a link to a lure page.

Can a user get infected just by visiting a legitimate website?

Yes. The advisory warns that visiting a compromised legitimate site can trigger infection, especially if the visitor has outdated security software installed.

What is a watering-hole attack in this campaign?

Attackers compromised 15 legitimate Korean websites across multiple industries and used them to redirect selected visitors to infrastructure that triggered software flaws and injected malicious code.

Are Lazarus and Gunra the same operation?

AhnLab reported that Lazarus and Gunra ran parallel campaigns against South Korean targets with different end goals, espionage versus ransomware extortion, while apparently sharing some tools.

Read the video transcript

In Korea, just opening the wrong “GaN semiconductor survey” email can end in ransomware on your PC. Lazarus-linked tools and Gunra ransomware ran side by side, using that fake survey and even normal Korean websites, watering-hole style, to hit mandatory banking security software. Here’s the nasty part: you can be infected just by visiting a compromised Korean site. The page silently redirects, triggers an old security plug-in, and slips code into normal Microsoft processes. If you get a GaN semiconductor survey email or see a trusted Korean site suddenly redirect, stop. Don’t click further, capture a screenshot and call our security team immediately.

Similar attacks