By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Hackers Use Korean Sites to Deploy Backdoors Via AnySign4PC

A sophisticated state-sponsored cyberattack campaign has been uncovered, leveraging compromised trusted domestic websites in South Korea to distribute malware. The operation, detailed by South Korean authorities and four cybersecurity firms, targeted users of locally installed financial-security software, specifically exploiting vulnerabilities in AnySign4PC. Attackers successfully used these compromised websites to deliver backdoors, identified as SIGNBT and COPPERHEDGE, to unsuspecting victims. A critical aspect of this attack is its ability to infect a system running a vulnerable version of AnySign4PC without requiring any user interaction or prompting the user for consent. This stealthy approach bypasses typical user security awareness, making it particularly dangerous.
The campaign's methodology involved injecting malicious code into legitimate web pages hosted on trusted Korean domains. When a user visited one of these compromised sites, the malicious script would automatically execute, initiating the exploitation of the AnySign4PC software. AnySign4PC is a widely used digital signature solution in South Korea, often mandated for online financial transactions and government services, making its compromise a significant threat to a broad user base. The attackers aimed to gain persistent access to the infected systems, likely for espionage, data theft, or further network infiltration. The specific versions of AnySign4PC targeted have not been publicly disclosed, but the exploit's success indicates a critical flaw in the software's handling of untrusted input or its update mechanisms.
Security researchers have attributed this campaign to a state-sponsored actor, suggesting a high level of sophistication and resources behind the operation. While the exact nation-state is not explicitly named in the initial reports, such attribution typically points to actors with significant geopolitical motivations. The use of trusted domestic websites as a distribution vector is a common tactic employed by advanced persistent threat (APT) groups to increase the likelihood of successful infection and evade detection by traditional security measures. The backdoors, SIGNBT and COPPERHEDGE, are known for their capabilities in maintaining covert access, exfiltrating data, and potentially serving as a pivot point for lateral movement within a compromised network. The investigation is ongoing, with authorities urging users to update their AnySign4PC software to the latest versions and to exercise caution when browsing online.
The implications of this attack extend beyond individual users, potentially impacting financial institutions and government agencies that rely on AnySign4PC for secure digital operations. The lack of user prompts during the exploitation phase highlights a severe security gap that attackers can exploit to bypass human vigilance. This incident underscores the ongoing challenges in securing critical digital infrastructure against advanced threats and the importance of robust vulnerability management and rapid patching by software vendors. The security firms involved are working to develop and distribute detection signatures and mitigation strategies to help protect users from further compromise. The incident serves as a stark reminder of the evolving tactics used by cybercriminals and state-sponsored actors to achieve their objectives in cyberspace.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.