Hackers Exploit AnySign4PC to Install Backdoors via Compromised Korean Websites

South Korean authorities, in collaboration with four security firms, have uncovered a state-sponsored cyber campaign that compromised trusted domestic websites to exploit vulnerabilities in locally installed financial-security software. This operation enabled attackers to infect targeted visitors with backdoors such as SIGNBT and COPPERHEDGE.

The attackers leveraged compromised web pages to exploit systems running vulnerable versions of AnySign4PC, a certificate-based electronic signature software. Notably, these infections occurred without any user prompts or downloads. The Korea Internet & Security Agency (KISA) identified versions 1.1.4.4 through 1.1.4.6 as affected and recommended upgrading to version 1.1.5.0 or later to mitigate the risk.

Security firm AhnLab reported evidence of related attacks across 72 organizations in 2026 and identified 15 legitimate websites used as watering holes. Their investigation revealed overlaps with previous attacks that culminated in the deployment of Gunra ransomware, including shared initial-access vulnerabilities, malware filenames, execution patterns, SSH key fingerprints, and network infrastructure. However, AhnLab clarified that this evidence does not conclusively attribute both operations to a single actor.

The joint advisory, issued by KISA, the National Intelligence Service, National Police Agency, and Financial Security Institute, emphasized the ongoing threat posed by state-sponsored phishing and watering-hole attacks. The advisory, based on analyses from AhnLab, S2W, ENKI Whitehat, and Plainbit, highlighted that such attacks continue to be identified, underscoring the need for vigilance.

ENKI Whitehat identified AnySign4PC as one of the exploited products, noting that attackers had utilized a zero-day flaw. Their observations traced the malicious activity back to the latter half of 2025, preceding KISA’s patch notice in June 2026.

AhnLab’s “Operation Double Barrel” report detailed an exploit chain involving four PNG images used to exchange keys, verify software versions, deliver version-specific exploit code, and report execution success. The malicious web pages communicated with the local security program via WebSocket, triggering a buffer overflow to execute shellcode. The payloads were then injected into legitimate Microsoft processes, leading to the installation of backdoors like Struggle (mapped to SIGNBT 3.0) or Brandoor (associated with COPPERHEDGE). These backdoors facilitated remote command execution, file theft, internal reconnaissance, process injection, and the delivery of additional payloads.

Plainbit’s forensic report reconstructed one of the watering-hole incidents, revealing that attackers mapped the victim’s internet-facing systems, compromised its website, installed a webshell, and inserted malicious JavaScript into a legitimate news article page. When a target visited the page, the vulnerable security program generated an error, creating a malicious DLL without any user interaction.

This incident underscores the critical importance of maintaining up-to-date software and exercising caution when visiting websites, even those considered trustworthy. Organizations should prioritize patching known vulnerabilities and implementing robust security measures to defend against sophisticated state-sponsored cyber threats.