Post
HIGH

Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts

· malware

South Korean authorities and four security firms disclosed a state-sponsored campaign that compromised trusted domestic websites to exploit a vulnerable, locally-installed financial security tool called AnySign4PC.

A compromised page could infect visitors running a vulnerable AnySign4PC version with SIGNBT or COPPERHEDGE backdoors without any user prompt, per The Hacker News. Both backdoors have prior associations with North Korean threat activity.