CyberSecurity SEE

Hackers Exploit AnySign4PC through Compromised Korean Sites to Install Backdoors Silently

Hackers Exploit AnySign4PC through Compromised Korean Sites to Install Backdoors Silently

South Korean Authorities Unveil State-Sponsored Cyber Attack Campaign Targeting Financial Security Software

In a concerning revelation, South Korean authorities, along with four security firms, have exposed a sophisticated state-sponsored cyber-attack campaign that compromised widely trusted domestic websites. The attackers employed these compromised sites to exploit vulnerabilities in locally installed financial-security software, ultimately infecting targeted users with backdoors known as SIGNBT and COPPERHEDGE.

Exploit Mechanics and Vulnerabilities

The compromised web pages had the potential to infect systems running vulnerable versions of AnySign4PC. Notably, a system running AnySign4PC versions 1.1.4.4 to 1.1.4.6 could be compromised without any user prompt for downloading, indicating a serious security flaw. The Korea Internet & Security Agency (KISA) has identified version 1.1.5.0 as the corrected release and has strongly recommended that users delete any vulnerable installations immediately.

AhnLab, another key player in the investigation, referred to the compromised products as "financial-security software A" and "I," but refrained from disclosing their specific identities, affected versions, or any vulnerability identifiers. This lack of detail raises concerns about the transparency and thoroughness of the advisory. According to AhnLab, the company uncovered evidence of related attacks across 72 organizations throughout 2026 and identified 15 legitimate websites that were manipulated as watering holes for these phishing endeavors.

The Nature of the Attacks

The joint advisory issued by KISA, alongside the National Intelligence Service, National Police Agency, and Financial Security Institute, was a culmination of an extensive analysis conducted with AhnLab and several other cybersecurity firms. KISA reported that similar state-sponsored phishing and watering-hole attacks have persisted, although it remains unclear whether raids on AnySign4PC continued after the release of the safe version, 1.1.5.0.

The attackers employed a range of tactics to lure their victims, sending out spear-phishing messages disguised as resumes, recruitment offers, investment materials, and industry surveys. They not only targeted financial institutions but also compromised sectors such as healthcare, education, and manufacturing—websites that their intended victims were likely to frequent.

Investigation and Evidence

ENKI Whitehat identified AnySign4PC as one of the vulnerable products and confirmed that the attackers utilized a zero-day vulnerability. Observations of the attack patterns extended back to the second half of 2025, indicating a long-standing threat before the June 2026 patch notice by KISA became available.

AhnLab’s report, dubbed "Operation Double Barrel," detailed a complex exploit chain that utilized four PNG images to exchange keys, ascertain the installed software version, deliver version-specific exploit code, and confirm whether the execution of the malicious code was successful. The attackers managed to communicate with the local security application via WebSocket, triggering a buffer overflow that executed shellcode on the victim’s system.

Once the initial compromise occurred, the attackers could inject the payload into legitimate Microsoft processes. Depending on the circumstances of the intrusion, they installed either Struggle, linked to the SIGNBT backdoor, or Brandoor, which corresponds to the COPPERHEDGE backdoor. Both malware types supported advanced capabilities such as remote command execution, file theft, internal reconnaissance, and more.

Interconnections with Ransomware

AhnLab noted unusual overlaps between the current campaign and previous ransomware incidents, particularly Gunra ransomware, which also exploited the aforementioned vulnerabilities. The investigators found substantial evidence of shared methodologies, including identical filenames, similar network infrastructure, and consistent anti-forensic practices, such as renaming files before deletion.

Nevertheless, AhnLab has refrained from definitively linking the latest operation to the notorious Lazarus Group. While the current advisories described the espionage-focused operators merely as a "state-sponsored threat group," separate reports from AhnLab and Kaspersky have previously documented Lazarus’s involvement in similar watering-hole attacks.

Recommendations and Future Implications

In light of these troubling findings, KISA issued a security notice, highlighting the urgent necessity for stakeholders to patch any instances of AnySign4PC vulnerable to buffer overflows that allow remote code execution. Organizations are recommended to actively monitor for signs of suspicious DLL loading, unusual service creation, and unexpected outbound SSH tunnels.

KISA’s ongoing vigilance in tracking such state-sponsored activities underscores the critical importance of cybersecurity in an increasingly digitized landscape. With these revelations, authorities and organizations are reminded of the paramount necessity for robust cyber defenses and the continuous vigilance required to protect sensitive financial data from emerging threats.

Source link

Exit mobile version