When Nation-States Become Ransomware Suppliers: The Next Stage in the Convergence of State and Criminal Cyberattacks

Last year I made the case that one of the most worrying changes taking place in the cyber threat landscape is the erosion of the boundary between nation-state cyber operations and financially motivated cybercrime.

A recent joint report by four South Korean intelligence and security agencies [Korean]into attacks attributed to North Korea's Lazarus Group and the Gunra ransomware operation points to something potentially far more significant than another nation-state experimenting with ransomware. It suggests that capabilities developed or operated by a nation-state may be finding their way into the commercial ransomware ecosystem.

If the evidence continues to point in this direction, we are no longer simply dealing with ransomware gangs becoming more sophisticated, or nation-states occasionally moonlighting as cybercriminals. We may be watching the emergence of an ecosystem in which state-developed capabilities, criminal infrastructure, access brokers, ransomware operators and geopolitical objectives have become interchangeable components of the same attack economy.

That development would change how organisations need to think about cyber risk.

We Have Been Heading Here for Some Time

Back in 2024, I wrote a two-part series examining the blurring boundary between nation-state threat actors and ransomware gangs.

In the first article, The worrying increased collaboration between nation-states and ransomware gangs, I looked at the historical distinction between financially motivated ransomware attacks and destructive operations conducted by nation-states.

At the time I wrote that article the line was already starting to blur. Ransomware had evolved from relatively small groups developing and operating their own malware into a sophisticated service economy. Ransomware-as-a-Service platforms allowed affiliates to effectively rent the capabilities required to conduct attacks, while Initial Access Brokers created a market for something even more valuable: established access to victim environments.

At the same time, nation-state actors were using techniques traditionally associated with cybercrime. In the second article, Nation-state threat actors, ransomware gangs, and cyber resilience, I examined examples ranging from Iranian state-aligned actors collaborating with ransomware operations to North Korean groups deploying ransomware themselves.

The direction of travel was already clear: governments and criminals did not necessarily need to belong to the same organisation to benefit from each other’s capabilities.

Iranian state-aligned Pioneer Kitten, for example, was observed gaining access to organisations and collaborating with ransomware groups including ALPHV/BlackCat, NoEscape and Ransomhouse. Its involvement reportedly extended beyond simply providing access into facilitating encryption and extortion.

North Korean actors were similarly combining espionage, financial crime and ransomware. I returned to the subject in Geopolitical crises bring state and commercial hackers together after researchers linked the North Korean state-sponsored Jumpy Pisces/Andariel group with the Play ransomware operation.

The interesting aspect of that case was the apparent division of labour. A sophisticated state-backed actor could gain access to an organisation, while a commercially motivated ransomware operator could monetise that access. It was effectively cybercrime specialisation.

Like any mature industry, participants did not need to manufacture every component themselves, they could leverage a supply-chain.

Operation Double Barrel May Show the Relationship Reversing

The latest research reported by The Record potentially takes this evolution another step.

Research from AhnLab, has identified significant technical overlap between campaigns attributed to North Korea’s Lazarus Group and the Gunra ransomware operation. The campaigns reportedly targeted South Korean organisations between 2025 and the first half of 2026. Most tellingly, the campaigns appear to have used many of the same components.

Researchers identified identical malware filenames and execution arguments, common privilege-escalation tooling, the same command-and-control infrastructure and even the same SSH key fingerprint. The attackers also apparently used the same technique for deleting malware after execution.

While those are significant similarities, AhnLab has quite correctly stopped short of claiming that Lazarus and Gunra are necessarily the same operators. The evidence could indicate collaboration, shared infrastructure or some form of access brokering.

The implication is important to defenders capabilities are moving between the state and criminal ecosystems.

The Direction of Travel Matters

Until now, many examples of state and criminal convergence have involved state actors taking advantage of the extraordinarily mature cybercrime ecosystem. Why build ransomware infrastructure when you can become an affiliate of an existing Ransomware-as-a-Service platform. There is simply no point when another organisation already has payment infrastructure, negotiators, leak sites and money-laundering mechanisms.

North Korean actors have previously been associated with Play, Qilin and Medusa ransomware operations. In February, researchers also reported Lazarus-linked actors deploying Medusa ransomware against organisations in the United States and Middle East. A case of a nation-state consuming capabilities from the criminal ecosystem.

Operation Double Barrel demonstrates the relationship working in the opposite direction. Here, the evidence suggests state-sponsored hackers may have supplied tooling, exploits or access to a ransomware group, rather than simply participating as affiliates within an established ransomware operation.

If this model becomes normalised, the implications could be significant. A nation-state discovers or develops an exploit and initially uses it against targets of intelligence or geopolitical interest. Once that operation has achieved its objectives, however, the capability may still retain considerable value. Access can be transferred. Infrastructure can be shared. Tooling can be reused.

A compromised organisation with little remaining intelligence value may still have considerable financial value to a ransomware operator. Equally, disrupting that organisation may serve a wider strategic purpose. The same access could therefore move through different phases of exploitation: first espionage, then monetisation or disruption.

The same initial compromise could therefore support very different outcomes depending upon who ultimately receives access. For one victim, espionage. For others, intellectual-property theft, cryptocurrency theft, ransomware or destruction disguised as ransomware.

The initial attack path may be almost identical. The objective at the end of it may be completely different. That makes traditional broad assumptions about threat actors’ motivations and intent potentially risky..

Attackers Are Becoming Supply Chains

As someone who focuses on cyber resiliency transformation, I frequently talk to customers about defending their own supply chains. We also need to spend more time thinking about the attacker’s supply chain.

Modern cybercrime is already highly specialised. One actor steals credentials. Another operates an infostealer. Another scans the internet for vulnerable infrastructure. Another develops exploits. An Initial Access Broker establishes persistence and sells access. A Ransomware-as-a-Service operator provides the encryption platform. An affiliate conducts the attack. Someone else negotiates the ransom. Another organisation launders the cryptocurrency.

What Operation Double Barrel shows is that the supply chain is something considerably more concerning: the resources and capability of a nation-state.

A government does not need to formally employ a ransomware gang for the ransomware ecosystem to benefit from its capabilities. Relationships can be deliberately cultivated while maintaining plausible deniability. Several governments have long tolerated cybercriminal organisations operating from within their borders, particularly where their extortion activities align with, or at least do not conflict with, national interests.

The result is not necessarily a centrally controlled alliance, but rather something far harder to deal with: an ecosystem.

Attribution Becomes Less Useful During the Crisis

When ransomware suddenly detonates across thousands of systems at two o'clock in the morning, one question inevitably comes from the SOC and the executive team alike: "Who is attacking us?"

Threat intelligence remains enormously valuable, but attribution needs to be separated from the immediate operational problem. If the infrastructure, exploits, tooling and access are being exchanged between actors, the ransomware brand displayed on the ransom note tells us less about the capability of the adversary that gained access to the environment.

You may apparently be responding to a relatively new ransomware group while the initial compromise was performed using infrastructure and techniques associated with one of the world’s most capable state-backed threat actors.

Equally, something that looks like ransomware may ultimately have an entirely different objective. We have seen this before: NotPetya masqueraded as ransomware while functioning as a destructive attack. WhisperGate similarly presented victims with a ransom demand despite the destruction being effectively irreversible. Iranian and Chinese-aligned actors have also used ransomware or ransomware-like activity to obscure espionage and destructive operations.

The ransom note therefore cannot be allowed to define the incident.

Ransomware describes what happened to some of your systems. It does not necessarily tell you why the attacker is there, what else they have done, or what they intend to do next.

The Implication for Threat Intelligence

I recently wrote about how agentic AI may disrupt some of our assumptions around cyber threat intelligence and the Pyramid of Pain. Threat intelligence works particularly well when adversaries exhibit sufficiently consistent behaviours that defenders can recognise and track them. But what happens when capabilities become composable from an ecosystem?

  • An exploit comes from one actor.

  • Infrastructure belongs to another.

  • Initial access is provided by a third.

  • Ransomware comes from a fourth.

  • Parts of the operation may be dynamically generated or adapted using AI.

The idea of a single threat actor with a relatively stable collection of tools, infrastructure and TTPs becomes much harder to maintain. The attack starts looking less like a fingerprint and more like a box of Lego, where components can be rearranged for every operation.

Threat intelligence needs to help us understand capabilities, infrastructure, relationships and attack paths, rather than simply attaching a familiar name to an intrusion through attribution.

Your Threat Model Probably Needs to Change

There is a temptation to look at Lazarus and conclude that this is primarily a problem for governments, defence companies, cryptocurrency exchanges or strategically important organisations that would be a potentially catastrophic oversight in cyber risk management.

Your organisation may simply need to be valuable enough for someone else to monetise the access afterwards, or for its disruption to contribute to wider economic damage and declining public confidence within the victim country.

Nor does an organisation need to be particularly large. The scale and industrialisation of modern ransomware make it possible for thousands, potentially tens of thousands, of organisations to be targeted across a campaign. An organisation may consider itself too small to attract the attention of a nation-state, but strategic effects can be cumulative. Disrupting a single organisation responsible for one per cent of a country's GDP may create significant impact; so can disrupting thousands of smaller organisations whose individual economic contribution appears insignificant.

From the perspective of the victim, those scenarios look very different. From the perspective of a nation-state seeking economic disruption, social instability or loss of confidence, they may contribute towards the same strategic objective.

Historically, organisations could make reasonably different assumptions about their adversaries. A small commercial organisation might sensibly conclude that it was unlikely to face the resources of a nation-state. A defence contractor might make a very different assumption.

Those threat models become less reliable when sophisticated capabilities migrate into a shared ecosystem. You no longer necessarily need to be the intended target of a nation-state to encounter nation-state capability. This should change how boards think about cyber risk.

Prevention Alone Becomes a Difficult Bet

None of this means organisations should stop investing in prevention, but it does mean we should stop assuming prevention will always work.

In my earlier articles, I argued that the growing convergence between nation-states and ransomware groups should make cyber resilience an important priority. The adversary is becoming too capable, too well resourced and too adaptive for any organisation to assume that prevention will always succeed.

Having spent decades working in the defence and intelligence sector, I have seen the extraordinary levels of security required when defending against determined nation-state adversaries. Replicating that level of protection across a commercial enterprise would impose enormous cost and friction while constraining the agility businesses depend upon to compete. For many organisations, the result would be commercially unsustainable; for others, it would make them considerably less competitive.

That leaves organisations with an uncomfortable reality. They must continue investing in prevention while recognising that there are practical limits to how far prevention can be taken. Cyber resilience addresses what happens beyond those limits. Organisations need to stop their current budget cycle and ask “What happens when an attacker better than the one we designed our controls to stop gets through them?

That is the cyber resilience question, and it leads to some uncomfortable follow-on questions.

  • Can we still investigate if our EDR infrastructure has been disabled?

  • Can we operate if identity infrastructure has been compromised?

  • Can we determine the attack timeline without trusting the systems the attacker controlled?

  • Can we identify persistence that may have existed for months?

  • Can we establish a Last Trusted State?

  • Can we recover our security and IT control plane before attempting large-scale production recovery?

  • Can we determine which business services must return first?

  • Can we rebuild them into an environment we actually trust?

  • Have we ever proved that any of this works under realistic conditions?

These are very different questions from asking whether we have backups.

Recovery Must Assume a Capable Adversary

This is perhaps the most important implication. Traditional disaster recovery assumes infrastructure has failed. Cyber recovery must assume infrastructure has been made to fail by someone who may still be inside it.

That is why recovery from destructive cyberattacks cannot simply mean restoring the most recent backup. We need an investigatory process capable of understanding what happened, establishing the scope of compromise, identifying the vulnerabilities and control failures that enabled it, hunting for persistence and determining when systems can actually be trusted again.

Only then can recovery safely accelerate. Otherwise, we risk recovering the attacker along with the business.

The Strategic Shift

For years we have divided cyber adversaries into convenient categories.

  • Cybercriminal.

  • Hacktivist.

  • Nation-state.

  • Insider.

Each came with assumptions about motivation, capability, targeting and behaviour. Those categories are becoming progressively less useful.

The infrastructure of cybercrime has become commercialised. Ransomware has become a service. Access has become a commodity. Attack tooling is shared, leaked and sold. State actors use criminal services. Criminal actors may benefit from state capabilities. More recently geopolitical conflict has created more incentives for governments to tolerate, encourage or cooperate with actors capable of imposing economic damage on their adversaries.

Operation Double Barrel leaves important questions about the precise relationship between Lazarus and Gunra unanswered. The strategic implication does not depend upon resolving them. What matters is that the barriers separating state and criminal cyber ecosystems continue to erode, allowing capabilities developed in one to appear increasingly readily in the other.

Having worked with hundreds of organisations after their data was encrypted or wiped, I have found that the precise relationship between the people on the other side of the keyboard matters far less to the victim than the consequences of the attack. Understanding who the adversary is and how they operate can be extremely valuable in directing investigation and threat remediation. For executives facing prolonged outages, disrupted operations and mounting financial losses, however, the immediate concern is the damage being inflicted and how quickly the organisation can recover. Whether those capabilities came from a nation-state, a ransomware group or some combination of the two does little to change the impact being experienced by the victim.

Cybersecurity strategies built around keeping a known class of attacker outside the perimeter are therefore becoming fragile.

  • We need to assume that sophisticated capabilities will continue to diffuse across the attacker ecosystem.

  • We need to assume that attribution during an incident may be uncertain.

  • We need to assume that an apparently financially motivated intrusion may have other objectives.

  • We need to assume that sometimes the attacker will succeed.

The organisations that survive those attacks will not necessarily be those that correctly guessed which threat actor would target them. They will be the organisations that built the capability to continue operating, investigate what happened and recover to a trusted state regardless of who was responsible.

Next
Next

When the Pyramid Starts to Move: How Agentic AI Changes the Value of Cyber Threat Intelligence