Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-07-30 ยท updated: 2026-08-18 ยท tags: [cyber, digest-2026-07-31, south-korea, anysign4pc, watering-hole, backdoor, state-sponsored] ยท confidence: not-rated ยท affected_sectors: [] ยท au_impact: false

Hackers Exploit AnySign4PC via Compromised Korean Websites to Install Backdoors

Summary

South Korean authorities and four security firms disclosed a state-sponsored campaign that compromised trusted domestic websites to exploit locally installed financial-security software (AnySign4PC). Infected visitors received SIGNBT or COPPERHEDGE backdoors without any user prompt or download. AhnLab identified evidence of related attacks at 72 organisations in 2026 and found 15 legitimate websites used as watering holes.

Key Details

  • Date: 2026-07-30
  • Source: The Hacker News
  • Reliability: Tier 2/4 โ€” Established cyber journalism
  • Campaign Type: State-sponsored watering hole
  • Target Software: AnySign4PC (financial security software)
  • Backdoors Deployed: SIGNBT, COPPERHEDGE
  • Scope: 72 organisations attacked in 2026; 15 legitimate websites used as watering holes
  • Attribution: South Korean authorities and four security firms
  • Infection Vector: No user prompt or download required โ€” drive-by download from compromised sites

Source

See Also

  • North Korea's Lazarus Group Sharing Tools with Ransomware Hackers
  • DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
  • SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT