HackMyIP
← Back to News
2026-07-30 The Hacker News

AnySign4PC Zero-Day Exploited via Hacked Korean Sites to Plant Backdoors

APTZero-DayMalware

A joint advisory from South Korea's Korea Internet & Security Agency (KISA), the National Intelligence Service, the National Police Agency, and the Financial Security Institute warns of a state-sponsored campaign that compromised at least 15 trusted domestic websites to weaponize locally installed financial-security software against unsuspecting visitors. The attackers exploited a previously unknown vulnerability in AnySign4PC — a certificate-based electronic signature tool widely used across South Korean enterprises — to silently deploy the SIGNBT and COPPERHEDGE backdoors. Affected versions span 1.1.4.4 through 1.1.4.6; KISA recommends deleting vulnerable installations and upgrading to version 1.1.5.0, which was patched in June 2026 after ENKI Whitehat observed exploitation as early as the second half of 2025. The advisory was issued alongside analysis from AhnLab, S2W, ENKI Whitehat, and Plainbit.

The technical exploit chain, documented by AhnLab in its "Operation Double Barrel" report, used four PNG images to exchange cryptographic keys, fingerprint the installed software version, deliver version-specific exploit code, and exfiltrate success telemetry. Once a victim loaded a compromised page, the malicious script communicated with the local AnySign4PC process over WebSocket, triggered a buffer overflow to execute shellcode, and injected the final payload into legitimate Microsoft processes — all without any user prompt or explicit download. AhnLab also identified parallel spear-phishing lures disguised as resumes, investment briefs, recruitment pitches, and industry surveys, broadening the threat actors' likely initial-access footprint beyond the watering-hole vector.

AhnLab reports evidence of related activity across 72 organizations in 2026, alongside overlap with intrusions that culminated in Gunra ransomware deployment. The shared indicators — identical initial-access vulnerability, matching malware filenames, identical SSH key fingerprints, and reused network infrastructure — strongly suggest coordinated tradecraft, though AhnLab stopped short of attributing both operations to a single actor. Two of the exploited products are referenced only as "financial-security software A" and "I," with affected versions and CVE identifiers withheld from public disclosure. Defenders investigating suspicious endpoint behavior can validate exposure with a port scanner to surface unexpected listeners and a DNS leak test to reveal unauthorized resolver activity that often accompanies second-stage C2 callbacks.

KISA notes that state-sponsored watering-hole and phishing operations of this kind remain active and have continued to surface even after the patch shipped. Organizations running AnySign4PC — or any environment using similar certificate-signing utilities — should immediately inventory installations, remove vulnerable versions, deploy the 1.1.5.0 update, and audit endpoints for indicators such as anomalous WebSocket connections originating from locally signed processes. Security teams are also advised to harden browser isolation for high-value targets, monitor outbound traffic from document-signing workstations, and confirm update integrity using an SSL/TLS checker to ensure patches are fetched from authentic vendor infrastructure rather than a spoofed mirror.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →