Skip to content
feed: live
>_ 0dayNews
threat intel
● Breaking

AnySign4PC Exploited in Korean Watering Hole Campaign

State-sponsored attackers compromised trusted Korean websites to exploit AnySign4PC financial software, silently installing SIGNBT or COPPERHEDGE backdoors without user interaction.

AnySign4PC Exploited in Korean Watering Hole Campaign
Image: 0dayNews / 0dayNews Editorial · All rights reserved
airgap airgap · Published · 1 min read

Confirmed. South Korean authorities and four security firms disclosed a state-sponsored campaign this week: trusted domestic Korean websites compromised, visitors running a vulnerable AnySign4PC build silently infected — no user prompt required.

The leverage point

AnySign4PC is financial security software required by Korean banking and government platforms for compliance. It runs on millions of Korean endpoints with elevated trust. Users did not choose to install it — financial site access required it.

That’s what made it the delivery vehicle. A compromised page triggers exploitation of the vulnerable software process without a download dialog or confirmation prompt. The attack surface isn’t the browser. It’s the trusted compliance process already running in the background.

Payloads observed

SIGNBT and COPPERHEDGE backdoors were delivered via the compromised sites.

SIGNBT: Previously attributed to North Korea’s Lazarus Group by Kaspersky and ESET in separate, documented campaigns. Confidence on those prior attributions: high. Confidence that this specific campaign originates with the same actor: not confirmed in the joint disclosure — treat accordingly.

COPPERHEDGE: Documented DPRK APT tooling across multiple independent incident reports. Same confidence caveat applies here.

South Korean authorities characterized the campaign as state-sponsored. No specific threat group was named in the current disclosure. Both payloads point the same direction. Awaiting independent corroboration on group attribution.

Who is exposed

Visitors to compromised Korean domestic websites while running a vulnerable AnySign4PC version. The affected version range is not specified in current reporting. The disclosure does not name which websites were compromised.

Action items

  1. Verify AnySign4PC is at the latest patched release. Check the vendor’s release notes for security fixes.
  2. Search endpoint telemetry for SIGNBT and COPPERHEDGE indicators of compromise.
  3. Review AnySign4PC process logs for unexpected outbound network connections.
  4. If MNIT- or finance-sector-adjacent: treat this as active until authorities release a clean scope.

Source: The Hacker News. Joint disclosure by South Korean authorities and four security firms — full technical details pending.

Found this useful? Share it.