VMTech
Discuss a project

Hacked Korean websites exploited AnySign4PC to deploy backdoors without user action

Hacked Korean websites exploited AnySign4PC to deploy backdoors without user action

On July 30, 2026, South Korean authorities disclosed a campaign in which compromised domestic websites exploited AnySign4PC versions 1.1.4.4–1.1.4.6. Merely visiting a malicious page could install SIGNBT or COPPERHEDGE without a prompt; KISA lists 1.1.5.0 as the fixed release.

Trusted websites became the delivery channel

AhnLab identified related attack evidence at 72 organizations and found 15 legitimate watering-hole sites in 2026. The figure does not represent 72 equally confirmed full compromises, but it shows the breadth of the activity.

The operation reflects borrowed trust as a core cyberattack tactic because attackers converted familiar news, healthcare, education and manufacturing sites into silent entry points. Organizations using locally required financial-security software were exposed even when employees avoided downloads and suspicious attachments.

How the exploit chain worked

AhnLab described four PNG images used to exchange keys, check the installed software version, deliver matching exploit code and report execution. The page contacted AnySign4PC over WebSocket, triggered a buffer overflow and injected shellcode into legitimate Microsoft processes.

Plainbit found that one compromised site served malicious JavaScript from a genuine news page. The resulting backdoor decrypted later stages in memory, injected code into svchost.exe and obtained command-and-control data from the Windows registry. Attackers later used Mimikatz, RDP, privilege-escalation exploits and NLBrute for lateral movement.

Attribution and defensive action

The evidence overlaps with Gunra ransomware incidents through infrastructure, filenames, an SSH-key fingerprint and injection into SyncHost.exe. AhnLab considers a technical link likely but does not claim that one operator ran both campaigns. The broader operation also remains formally attributed only to an unnamed state-sponsored group, not Lazarus.

For businesses, patching is only the first step: remove vulnerable AnySign4PC installations or move to 1.1.5.0, then preserve and examine process memory, command lines, registry values, DLL-load events and network records. Hunt specifically for in-memory PE execution, injection into SyncHost.exe or svchost.exe, unusual services and unexpected outbound SSH tunnels.

#cybersecurity#anysign4pc#wateringhole#malware
Open analytics
On the site 1 views
min read 3 31.07.2026
On Instagram 1 views
Instagram

Hacked Korean websites exploited AnySign4PC to deploy backdoors without user action

Open the post on Instagram ↗