AnySign4PC Zero-Day Watering Holes Hit 72 South Korean Organizations

A state-sponsored campaign used hacked South Korean websites to exploit an AnySign4PC zero-day and infect visitors with SIGNBT and COPPERHEDGE backdoors.
Table of Contents
    Add a header to begin generating the table of contents

    A state-sponsored campaign compromised trusted South Korean websites to exploit a zero-day buffer overflow in AnySign4PC, a certificate-based electronic-signature program, and infect visitors with either the SIGNBT or COPPERHEDGE backdoor. South Korean authorities and four security firms jointly disclosed the drive-by operation, which AhnLab documented as hitting 72 organizations through 15 watering-hole sites.

    Operation Double Barrel: Exploiting AnySign4PC Through Trusted Sites

    South Korea’s internet security agency KISA, the National Intelligence Service, the National Police Agency, and the Financial Security Institute disclosed the campaign alongside AhnLab, S2W, ENKI Whitehat, and Plainbit. A compromised page could infect a system running a vulnerable AnySign4PC version without a prompt or a user-initiated download. ENKI Whitehat identified the product and said the attackers exploited a zero-day flaw, describing it as a buffer overflow that permits remote code execution. KISA lists versions 1.1.4.4 through 1.1.4.6 as affected and 1.1.5.0 as the fixed release.

    The Four-PNG Exploit Chain and WebSocket Delivery of Version-Specific Shellcode

    AhnLab’s “Operation Double Barrel” report describes an exploit chain that used four PNG images to exchange keys, check the installed software version, deliver version-specific exploit code, and report success back to the malicious page. The page communicated with the local security program over WebSocket and triggered the buffer overflow to execute shellcode injected into legitimate Microsoft processes. Because the infection ran through the locally installed financial-security software, activity that began in the second half of 2025 went largely unnoticed by end users.

    SIGNBT and COPPERHEDGE Backdoors Behind the 72-Organization Intrusion Wave

    Depending on the intrusion, the attackers installed Struggle, mapped to SIGNBT 3.0, or Brandoor, mapped to COPPERHEDGE. Both support remote command execution, file theft, internal reconnaissance, process injection, and delivery of additional payloads. AhnLab identified evidence of related attacks at 72 organizations and found 15 legitimate websites used as watering holes, with lure themes including fake resumes, recruitment approaches, investment material, and industry surveys.

    The Gunra Ransomware Overlap Points to a Shared Vulnerable Access Path

    AhnLab found a notable technical overlap between the espionage campaign and Gunra ransomware. The two share the same initial-access vulnerability and compromised healthcare website, the same filenames net.tmp and inet.tmp, the same SSH public-key fingerprint, the same reverse-tunnelling address, and the same exploit-script distribution domain jshosting[.]me. AhnLab assesses a likely technical link between the operators but could not determine the relationship between them.

    Plainbit independently reconstructed one incident in which attackers compromised a victim’s website, installed a webshell, and injected JavaScript into a legitimate news page. A scheduled task chain running RuntimeBroker to task.vbs to a renamed SSH client operating as SearchHost.exe established a reverse tunnel out of the network. The reconstruction shows a well-established access path that relies on trusted infrastructure rather than direct exploitation of victims’ workstations.

    KISA Patch Guidance and What Defenders Should Hunt For

    KISA recommends updating AnySign4PC to version 1.1.5.0 or deleting vulnerable installations, and its patch notice lists no CVE identifier for the flaw. The joint advisory advises defenders to hunt for suspicious DLL loading by legitimate executables, in-memory PE execution, injection into SyncHost.exe or svchost.exe, and unexpected outbound SSH tunnels, and to preserve process memory and network records before containment.

    Why the AnySign4PC Zero-Day Expands the Espionage Target Surface

    AnySign4PC is a widely installed financial-security product in South Korea, which means the zero-day gave the operators a no-prompt infection path across a large installed base through sites users already trust. The combination of a drive-by exploit with a locally installed signature program reduces the user awareness that usually interrupts watering-hole attacks. The same vulnerable access path now appears to be shared by an espionage operator and a ransomware operator, which suggests that exploit infrastructure for this product has circulated beyond a single team and is available to multiple threat groups.

    Attribution Analysis Stops Short of Naming a Group

    The joint disclosure stops short of formally naming a group for this campaign. AhnLab has separately attributed an earlier AnySign4PC watering-hole attack to the Lazarus group, and Kaspersky documented prior Lazarus use of AnySign4PC, SIGNBT, COPPERHEDGE, and watering holes during an operation it tracked as SyncHole. The backdoor families themselves, and the reuse of a financial-software attack surface, align the campaign with patterns long associated with North Korean intrusion operations, even though the official attribution language remains cautious.

    Related Posts