< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-07-30T16:03:15+05:30

State-Sponsored Hackers Exploit AnySign4PC Vulnerability via Compromised Korean Websites to Deploy Backdoors

State-sponsored attackers exploited a buffer overflow vulnerability in AnySign4PC through compromised Korean websites to install backdoors without user interaction. The campaign, linked to groups like Lazarus, used watering-hole attacks and shared infrastructure with Gunra ransomware operations.

South Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The attackers used those sites to exploit locally installed financial-security software and infect targeted visitors with SIGNBT or COPPERHEDGE backdoors.

A compromised page could infect a system running a vulnerable AnySign4PC version without a prompt or

Read original article

*** END OF TRANSMISSION ***