South Korean authorities, alongside four major security firms, have revealed a sophisticated state-sponsored cyber campaign targeting domestic websites. The attack leveraged these websites to exploit financial-security software, compromising visitors’ systems with SIGNBT or COPPERHEDGE backdoors.
Exploiting Vulnerabilities in AnySign4PC
The campaign targeted systems running vulnerable versions of AnySign4PC, a software used for secure electronic transactions. According to the Korea Internet & Security Agency (KISA), versions 1.1.4.4 through 1.1.4.6 are affected, with version 1.1.5.0 addressing the flaw. Users are advised to uninstall vulnerable versions to mitigate risks.
Security firm AhnLab identified attacks across 72 organizations in 2026, with 15 legitimate sites acting as watering holes. These incidents showed similarities with previous Gunra ransomware attacks, although no direct connection to a specific group was confirmed.
Methodology and Impact of the Cyber Attacks
The attacks, analyzed by KISA and other security organizations, involved spear-phishing tactics disguised as job applications and surveys. Attackers infiltrated various sectors, including healthcare and education, exploiting poor security measures on targeted websites.
ENKI Whitehat noted the exploitation of a zero-day vulnerability in AnySign4PC. This flaw was actively used from late 2025 until KISA’s patch release in June 2026. Attackers employed PNG images in an exploit chain to compromise systems, delivering payloads through legitimate processes like svchost.exe.
Continued Threats and Security Recommendations
Despite the release of a patched version, KISA reports ongoing attempts to exploit these vulnerabilities. Security firms recommend monitoring for suspicious DLL activities and unusual network patterns. AhnLab highlights the importance of behavioral analysis over static indicators due to the nature of the malware’s operations.
Additionally, there is a potential supply-chain risk, as some compromised sites were linked to the same development firm. While no direct compromise of the company’s systems was confirmed, the possibility remains under investigation.
Future Outlook and Preventative Measures
As cyber threats evolve, the importance of timely updates and robust security protocols cannot be overstated. Organizations are urged to patch vulnerable software promptly and enhance their network monitoring strategies to detect and mitigate potential threats effectively.
The ongoing investigation into these attacks underscores the need for vigilance and collaboration among cybersecurity agencies to combat the growing sophistication of state-sponsored cyber threats.
