[Joint Cybersecurity Advisory] Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware Group)
This technical analysis report was prepared as part of the joint cybersecurity advisory titled “Advisory on Cyberattacks Targeting Korean Citizens and Businesses by State-Sponsored Hacking Groups” issued by the Republic of Korea’s National Intelligence Service (NIS), National Police Agency (NPA), Korea Internet & Security Agency (KISA), and Financial Security Institute
Ransom & Dark Web Issues Week 3, July 2026
ASEC Blog publishes Ransom & Dark Web Issues Week 3, July 2026 DragonForce Ransomware Attack on a Saudi Arabian Chemical Manufacturer AiLock Ransomware Attack on Japan’s Largest Taxi and Limousine Operator Cyberattack on Japan’s Largest Frozen Food Company Disrupts the Wider Food Supply Chain
Analysis on the Case of TIDRONE Threat Actor’s Attacks on Korean Companies
AhnLab SEcurity intelligence Center (ASEC) has recently identified that the TIDRONE threat actor is launching attacks against companies. In the attack cases, Enterprise Resource Planning (ERP) software was exploited to install a backdoor malware called CLNTEND. TIDRONE is a threat group known for targeting Taiwanese defense companies and drone manufacturers.

