AnySign4PC Vulnerability: Backdoor Attack via Hacked Korean Websites – Veri Sızıntısı

Korean Sites Exploit AnySign4PC Flaw to Install Backdoors

State-sponsored hackers in South Korea are exploiting a critical vulnerability in the popular e-signature software AnySign4PC, using compromised legitimate websites to install backdoors on visitors' systems without user interaction.

A Korean website on a computer screen with a warning symbol, illustrating the AnySign4PC attack.

What Happened

South Korea's cybersecurity landscape has been shaken by a sophisticated attack campaign attributed to a state-sponsored group. According to a joint advisory from the Korea Internet & Security Agency (KISA), the National Intelligence Service, and four leading domestic security firms (AhnLab, S2W, ENKI Whitehat, and Plainbit), an unidentified group compromised trusted domestic websites. The attackers used these sites as "watering holes" to exploit locally installed financial security software and infect targeted visitors.

At the heart of the attack is a software called AnySign4PC, widely used for certificate-based electronic signature processes. The attackers exploited a previously unknown zero-day vulnerability in older versions of this software. This flaw allowed them to infect a user's system with malware without requiring any download confirmation or user interaction. Simply visiting a compromised news, healthcare, or educational website was enough for a system to become infected.

Security firm AhnLab announced that it had identified evidence related to this attack campaign at 72 different organizations in 2026. Additionally, 15 legitimate websites used by the attackers to reach their targets were identified. The attacks aimed to install backdoor software known as SIGNBT or COPPERHEDGE on victims' systems. These backdoors provide attackers with full control over the system, data theft capabilities, and the ability to move laterally within a network. The investigation also revealed that some elements of this attack chain overlap with the infrastructure and techniques used in previous Gunra ransomware attacks, although no definitive evidence has been presented to confirm that the same actor conducted both operations.

What Data Was Leaked

The joint advisory and the analyses from security firms do not contain specific information about the exact types of data stolen by the attackers or the volume of data exfiltrated. However, the capabilities of the backdoor malware installed on the systems, named SIGNBT and COPPERHEDGE, provide significant clues about the attackers' intentions. This malware provided the attackers with the following abilities:

  • Remote Code Execution: Attackers could gain full control over infected systems by remotely executing any commands they wished.
  • File Theft: They had the capability to identify, copy, and transfer any file from the victim's computer or its connected network to their own servers. This could mean the theft of sensitive information such as trade secrets, personal data, financial documents, or state secrets.
  • Internal Reconnaissance: From the initial compromised system, attackers could scan the organization's internal network to identify other valuable targets like servers and databases.
  • Delivery of Additional Payloads: They could use the existing backdoor to download more destructive malware, such as ransomware, onto the system.

Given these capabilities, the purpose of the attack appears to be long-term espionage and data theft. As such complex attacks usually target specific sectors or institutions, the nature of the stolen data could be highly critical. A comprehensive Data Breach Search could be a crucial step for individuals and organizations to check their status after such incidents.

How Did the Attack Happen

The attack was carried out as a complex, multi-stage chain. The techniques used by the attackers indicate a targeted and stealth-focused operation.

1. Initial Access: Phishing and Watering Hole
The attackers used two primary methods to reach their targets. The first was sending spear-phishing emails disguised as resumes, recruitment offers, investment materials, or industry surveys. The second, more effective method was hacking legitimate websites frequently visited by their targets, including news, healthcare, education, and manufacturing sites. Malicious JavaScript code placed on these sites turned anyone visiting them with a vulnerable version of AnySign4PC installed into a potential victim.

2. Vulnerability Exploitation: Zero-Day Flaw
When a victim visited a compromised webpage, the malicious code running in the background communicated with the locally installed AnySign4PC software via the WebSocket protocol. According to AhnLab's report, dubbed "Operation Double Barrel," this communication involved the use of four PNG image files. These files were actually used for: key exchange, checking the installed software version, delivering version-specific exploit code, and finally, reporting whether the execution was successful. At the end of this process, a buffer overflow vulnerability in the AnySign4PC software was triggered, allowing the attackers to execute their own code (shellcode).

3. Evasion and Installation: Process Injection
Once the attackers' code was executed, the malicious payload was not written directly to the disk. Instead, to evade detection, it was injected into legitimate Microsoft processes. Analysis by Plainbit revealed that the malicious DLL was created on the system without a download prompt and decrypted its subsequent stages in memory. The code was then injected into a trusted Windows process like `svchost.exe`. This technique is highly effective at bypassing security software.

4. Backdoor Installation: SIGNBT and COPPERHEDGE
In the final stage, one of two different backdoors was installed on the system, depending on the nature of the intrusion: Struggle, which AhnLab maps to SIGNBT 3.0, or Brandoor, known as COPPERHEDGE. These backdoors provided the attackers with persistent access, enabling data theft and further actions within the network. More information on such sophisticated attacks can be followed through up-to-date Data Breach News.

Who Was Affected

The attack campaign directly targeted institutions and organizations in South Korea. According to AhnLab's report, evidence related to the attack was found in 72 organizations during 2026. However, the report notes that this figure does not represent a tally of fully confirmed compromises, but rather an initial finding.

The profile of the websites used for the watering hole attack gives an idea of the intended audience. The attackers compromised news portals, healthcare providers, educational institutions, and manufacturing company websites. This indicates that the attackers were targeting people who work in these specific sectors or interact with these sites. In short, anyone with a vulnerable version of AnySign4PC installed who visited one of these compromised sites was a potential victim.

What You Can Do

There are concrete steps that both individual users and organizations can take to protect themselves from this attack or prevent a potential breach. The recommendations made by Korean authorities and security firms are as follows:

  • Check Your AnySign4PC Version: Check if you have AnySign4PC software installed on your system. According to KISA, all versions from 1.1.4.4 through 1.1.4.6 are vulnerable to this attack.
  • Update or Remove the Software: KISA's clearest recommendation is to completely uninstall the vulnerable versions from the system. Then, you should install version 1.1.5.0 or higher, which is stated to have the vulnerability patched. If you do not use the software, removing it entirely is the safest option.
  • Keep All Your Software Updated: This incident once again demonstrates how critical it is to keep not just security software, but also operating systems, browsers, and all other applications up to date.
  • Use Security Solutions: An advanced antivirus or EDR (Endpoint Detection and Response) solution can help detect suspicious activities like process injection and abnormal network traffic.
  • Be Cautious with Suspicious Emails: Since phishing was one of the attack vectors, avoid clicking on attachments and links in unexpected emails or those from unverified sources.

What the Company Is Saying

The source article does not include a direct statement from the developer of the AnySign4PC software. However, the most comprehensive information about the attack comes from a joint advisory report created by South Korean official agencies and the private security companies that investigated the incident.

In their joint statement, the Korea Internet & Security Agency (KISA), the National Intelligence Service, the National Police Agency, and the Financial Security Institute stated that such state-sponsored phishing and watering hole attacks continue to be identified. KISA explicitly warned users and organizations to immediately delete vulnerable AnySign4PC versions and upgrade to the secure version 1.1.5.0.

AhnLab, which contributed to the investigation, published its "Operation Double Barrel" report detailing the technical aspects of the attacks, the malware used, and the potential links to the Gunra ransomware operations. The firm ENKI Whitehat confirmed that the attackers exploited a zero-day vulnerability and that they had been observing this activity since the second half of 2025. This joint effort underscores the seriousness of the threat and the necessity of a public response.

Source

https://thehackernews.com/2026/07/hackers-exploit-anysign4pc-via-hacked.html

This content was generated with AI assistance through our Argus Flow application. We are continuously working to improve Argus Flow; if you encounter any issues such as translation errors, incorrect sources, or unverified information, you can report them using the button below. We appreciate your feedback.

Weekly Newsletter

Curated data breach news delivered to your inbox every week.