hacker-news · Crawled Jul 30, 2026

Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts

6 IoCs 2 Malware
Read original article ↗

AI Summary

A state-sponsored threat actor has conducted a campaign exploiting a zero-day buffer overflow vulnerability in AnySign4PC, a South Korean financial-security software, through compromised legitimate websites used as watering holes. The attack allows remote code execution without user interaction by leveraging malicious WebSocket communication and DLL side-loading, leading to the deployment of SIGNBT or COPPERHEDGE backdoors. These backdoors enable remote command execution, file theft, reconnaissance, and lateral movement using tools like Mimikatz and RDP. The campaign overlaps technically with Gunra ransomware operations in infrastructure and artifacts, though no formal attribution to a specific group like Lazarus is made in the joint advisory.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 6 extracted

Type Value Detail
IP 176[.]65[.]128[.]26 Details →
Domain jshosting[.]me Details →
Filename net.tmp Details →
Filename inet.tmp Details →
Filename task.vbs Details →
Filename SearchHost.exe Details →

MITRE ATT&CK TTPs 11 techniques