Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts
AI Summary
A state-sponsored threat actor has conducted a campaign exploiting a zero-day buffer overflow vulnerability in AnySign4PC, a South Korean financial-security software, through compromised legitimate websites used as watering holes. The attack allows remote code execution without user interaction by leveraging malicious WebSocket communication and DLL side-loading, leading to the deployment of SIGNBT or COPPERHEDGE backdoors. These backdoors enable remote command execution, file theft, reconnaissance, and lateral movement using tools like Mimikatz and RDP. The campaign overlaps technically with Gunra ransomware operations in infrastructure and artifacts, though no formal attribution to a specific group like Lazarus is made in the joint advisory.
AI-extracted · verify before operational use