importantSYS.SOURCE: The Hacker News• 2026-07-30T16:03:15+05:30
State-Sponsored Hackers Exploit AnySign4PC Vulnerability via Compromised Korean Websites to Deploy Backdoors
State-sponsored attackers exploited a buffer overflow vulnerability in AnySign4PC through compromised Korean websites to install backdoors without user interaction. The campaign, linked to groups like Lazarus, used watering-hole attacks and shared infrastructure with Gunra ransomware operations.
South Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The attackers used those sites to exploit locally installed financial-security software and infect targeted visitors with SIGNBT or COPPERHEDGE backdoors.
A compromised page could infect a system running a vulnerable AnySign4PC version without a prompt or
*** END OF TRANSMISSION ***