Hackers have launched a new cyber campaign by abusing a security flaw in AnySign4PC, a widely used digital authentication software in South Korea. Instead of directly targeting victims, the attackers first compromised trusted Korean websites and secretly injected malicious code into them. Anyone visiting these websites with a vulnerable version of AnySign4PC installed could become infected without clicking anything or approving a download. This attack was publicly disclosed by South Korean authorities along with multiple cybersecurity companies.

anysign4pc-security-update-kisa-vulnerability-patch

The attack works through a technique known as a watering hole attack, where hackers compromise websites that their intended victims are likely to visit. Once a visitor opens one of these infected websites, the hidden script communicates with the vulnerable AnySign4PC software running on the computer. The flaw then allows attackers to install malware silently, making the infection process almost invisible to the user. Security researchers confirmed that no warning message or download prompt appears during the attack.

According to the advisory, the attackers used this method to deliver two known backdoors called SIGNBT and COPPERHEDGE. These backdoors allow hackers to secretly access an infected system, steal sensitive information, execute commands, and maintain long-term control over the device. Once installed, the malware gives attackers the ability to perform espionage activities while remaining hidden from the victim. Researchers believe the campaign was carefully planned and designed to target specific users.

south-korea-anysign4pc-security-software-vulnerability

Investigators discovered that at least 15 legitimate South Korean websites had been compromised during the campaign. These included websites belonging to news organizations, healthcare providers, educational institutions, and manufacturing companies. Because these websites were trusted by visitors, users had no reason to suspect they were being exposed to malware. The attackers simply waited for people with vulnerable software to visit the infected pages before launching the exploit automatically.

The vulnerable versions of AnySign4PC identified by the Korea Internet & Security Agency are versions 1.1.4.4 through 1.1.4.6. The agency confirmed that version 1.1.5.0 fixes the security issue and strongly recommends updating immediately. Users who no longer need the software are also advised to uninstall it completely to reduce their exposure. Applying the latest security updates remains the most effective way to stop this attack.

north-korea-hacker-anysign4pc-cyberattack-south-korea

Security experts have linked the campaign to state-sponsored threat activity based on the tools, techniques, and malware used during the attacks. Previous research has connected similar operations involving SIGNBT and COPPERHEDGE to North Korea’s Lazarus group. However, investigators also found that a separate Gunra ransomware incident used the same vulnerability and attack path, although they stopped short of confirming that both operations were carried out by the same threat actor.

Researchers explained that this attack follows a pattern seen in previous campaigns targeting South Korea’s mandatory financial security software. Earlier operations abused other widely deployed authentication tools, showing that attackers continue to focus on software installed on millions of systems. By compromising trusted websites instead of individual users, hackers can infect multiple victims without sending phishing emails or convincing anyone to download suspicious files.

watering-hole-attack-malicious-code-injection-cybersecurity

This incident highlights how vulnerabilities in widely used security software can become valuable targets for advanced threat groups. Organizations should ensure all systems are running the latest version of AnySign4PC, monitor for unusual activity, and remove outdated software whenever possible. Users should also keep their devices updated and remain aware that even trusted websites can become part of sophisticated cyberattacks if attackers successfully compromise them.

Stay alert, and keep your security measures updated!

Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news