Cyber Security

Hackers Use AnySign4PC Using Korean Hacked Sites to Install Backdoors Without Notification

South Korean authorities and four security firms have uncovered a state-sponsored campaign that compromised trusted domestic websites. Attackers used those sites to exploit software installed in the financial security environment and infect targeted visitors with it SIGNBT or THE COPPERHEDGE which are behind.

A vulnerable page may infect a system running a vulnerable version of AnySign4PC without prompting or a user-initiated download. The Korea Internet & Security Agency (KISA) says AnySign4PC versions 1.1.4.4 to 1.1.4.6 are affected and lists version 1.1.5.0 as a fixed release. It recommends removing vulnerable installations.

AhnLab refers to the two exploited products only as A and I financial security software. Its report does not reveal its identity, affected or patched versions, or vulnerability identifiers.

AhnLab said it identified evidence of related attacks in 72 organizations by 2026. The company also found 15 legitimate websites being used as watering holes. Its investigation also found a conflict with the attack that ended with Gunra ransomware.

Shared evidence includes shared initial access vulnerabilities, malware file names and usage patterns, SSH key fingerprints, and network infrastructure. AhnLab said the evidence does not show that the same actor made both plays. The report does not say what evidence puts the organization in the figure, so the 72 is not a figure of equally assured consensus. The advice does not name the government-sponsored group.

A Page Visit Is Enough

Joint advisories were issued by KISA, the National Intelligence Service, the National Police Agency, and the Financial Security Institute, based on analysis conducted with AhnLab, S2W, ENKI Whitehat, and Plainbit.

KISA said phishing attacks and government-sponsored watering-holes continue to be seen. Public reports do not say whether attackers continued to exploit AnySign4PC after version 1.1.5.0 was available.

The attackers posted phishing messages disguised as resumes, recruitment methods, investment materials, and industry surveys. They also compromise news, health care, education, manufacturing, and small, poorly secured websites that their intended victims might visit.

ENKI Whitehat identified AnySign4PC, software used for certificate-based electronic signatures, as one of the vulnerable products and said the attackers exploited a zero-day flaw. ENKI saw work from the second half of 2025, before KISA published its notice of June 2026.

AhnLab’s Operation Double Barrel report describes a series of exploits that used four PNG images to exchange keys, check the installed software version, deliver version-specific exploit code, and report whether the execution was successful. The malicious page connected to the local firewall via WebSocket and triggered a buffer overflow to execute the shellcode.

The payload was then submitted to Microsoft’s official processes. Depending on the entry, attackers have installed To struggleAhnLab mapping to SIGNBT 3.0, or Brandoorits COPPERHEDGE backdoor name. The malware supports remote command execution, file hijacking, internal inspection, process injection, and payload delivery.

Plainbit independently reconstructed one of the waterhole incidents in its forensics report. The attackers mapped the victim’s Internet-facing systems, defaced his website, installed a webshell, and injected JavaScript into the official page of the news article. When the target visited it, the vulnerable security system generated an error and created a malicious DLL without a download prompt or other user interaction.

The resulting backdoor decrypted the latest sections in memory, added code to svchost.exe, and read command and control information from the Windows registry. Attackers then use privilege escalation exploits, Mimikatz and other authentication tools, Remote Desktop Protocol connections, and NLBrute to get through the network.

S2W’s analysis of the three malware clusters found a repeating pattern of DLL sideloading, encrypted registry blobs, and in-memory physical loading. Two batches released SIGNBT versions 0.0.1 and 1.2, while a third batch removed external payloads that researchers could not recover.

Gunra route

The Gunra ransomware entry of March 2026 used the same compromised healthcare website and a similar vulnerability in a product AhnLab calls financial security software A. Both government-sponsored chains and ransomware then injected code into SyncHost.exe. AhnLab does not identify software A, so the report does not indicate that the vulnerability linked to Gunra was AnySign4PC.

AhnLab also found that both operations used the filenames net.tmp and inet.tmp. The inet.tmp argument was identical, while the net.tmp arguments followed the same GUID format. Both operations used the same SSH public key fingerprint Qr1to32lQHxEu6phzNyrTZrU0iElrOfVWMBLnqoen24. They also use the same drag-back address of 176.65.128[.]26. Domain jshosting[.]I was used to distribute exploit scripts for both attack sets.

The attackers also followed the same anti-aliasing process, renaming the malicious files to random four-letter words before deleting them. Plainbit observed additional evidence destruction using SDelete and CCleaner.

AhnLab assessed whether the evidence showed a possible technical link but said it could not determine the relationship between the users. The company listed several possible explanations, including limited interoperability, shared tools or infrastructure, use of a common access vendor, or access to shared operating resources.

Overlap refers to a shared or reused access path from a compromised website through hosting and supporting infrastructure. They do not indicate that the same operator masterminded both attacks.

Gunra operates as a ransomware-as-a-service, according to separate research from S2W.

The company said the operation affected 32 companies as of March 9, 2026, including five South Korean businesses, and moved from Conti-derived ransomware to its Windows and Linux builds.

Attribution Stops Lazarus

The current government advisory report and Operation Double Barrel describe the operation as solely focused on espionage as a state-sponsored threat group. There is no text that says the complete campaign of 2025 to 2026 is from Lazarus, and it does not connect Lazarus with Gunra.

However, AhnLab attributed the March 2026 AnySign4PC vulnerability attack to Lazarus in a separate report published in April. Kaspersky also documented Lazarus using watering holes, South Korean security software, SIGNBT, and COPPERHEDGE during the earlier Operation SyncHole.

Those reports were written before Lazarus used the AnySign4PC, SIGNBT, COPPERHEDGE, and watering hole exploits. They don’t say that Operation Double Barrel or Gunra’s entry is caused by Lazarus.

Patch the Software, Hunt the Behavior

KISA’s June 1 security advisory identifies AnySign4PC versions 1.1.4.4 through 1.1.4.6 as vulnerable to a buffer overflow that allows remote code execution. It lists version 1.1.5.0 as a stable release and recommends removing the vulnerable installation.

Reports recommend hunting for suspicious DLL loading with legitimate executables, encrypted data stored under service registry entries, in-memory PE execution, unusual service creation, injection into SyncHost.exe or svchost.exe, and unexpected outgoing SSH tunnels.

ENKI discovered that its type 1 backdoor deleted its registry configuration, loader, and background files after copying them to memory when running in modes 1, 2, 4, or 5 with defense enabled. Once booted, the files were missing from disk until a clean shutdown restored them, and the restored loader had a different hash. That makes behavioral telemetry more useful than a static file pointer.

Plainbit observed a string of persistence where a scheduled task called RuntimeBroker launched task.vbs, which then used an SSH client renamed SearchHost.exe to establish a reverse tunnel. S2W advises saving process memory, command lines, registry values, DLL load events, and network logs before terminating processes or partitioning systems.

AhnLab also found that several vulnerable websites were linked to the same development and management company, which it described as a possible conduit for procurement. Available evidence does not confirm that the company’s source code, software update process, or central administration platform was compromised.

KISA’s June 1 notice does not list a CVE indicator for the AnySign4PC flaw. As of July 30, 2026, The Hacker News found only CVE-2020-7882 in the Public CVE Program and NVD searches for AnySign4PC, an unrelated directory vulnerability affecting older versions. That result does not remove a reserved, unpublished, or otherwise defined identifier. The AhnLab A software is also unknown in its report, and does not reveal its affected or fixed versions.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button