State-Sponsored Hackers Exploit AnySign4PC via Compromised Korean Websites
A state-sponsored campaign has compromised trusted South Korean websites to exploit the AnySign4PC financial security software, installing backdoors without user interaction.
South Korean authorities and multiple cybersecurity firms have revealed a sophisticated state-sponsored campaign that leveraged compromised domestic websites to target users. The attackers exploited vulnerabilities in the AnySign4PC financial security software, a common tool for digital signatures in South Korea, to install SIGNBT or COPPERHEDGE backdoors onto victim systems. This tactic allowed for infection without requiring any user interaction or even a prompt, highlighting the severe risks associated with supply-chain attacks targeting widely used local software.
The Korea Internet & Security Agency (KISA) identified specific versions of AnySign4PC, ranging from 1.1.4.4 through 1.1.4.6, as vulnerable, recommending the removal of affected installations and noting version 1.1.5.0 as the patched release. Security firm AhnLab reported observing related attacks affecting 72 organizations and identified 15 legitimate websites used as watering holes for these malicious activities. The investigation also uncovered overlaps with previous attacks that deployed Gunra ransomware, sharing commonalities such as initial-access vulnerabilities, malware filenames, execution patterns, and network infrastructure.
The attack chain, as detailed by AhnLab, involved a series of four PNG images used to exchange encryption keys, verify the installed software version, deliver tailored exploit code, and confirm successful execution. The malicious web pages communicated with the local security program via WebSocket, triggering a buffer overflow vulnerability to execute shellcode. This shellcode was then injected into legitimate Microsoft processes, leading to the deployment of either the SIGNBT 3.0 variant (referred to as Struggle by AhnLab) or the COPPERHEDGE backdoor (named Brandoor by AhnLab).
These backdoors provided attackers with extensive capabilities, including remote command execution, file theft, internal network reconnaissance, process injection, and the ability to deliver further malicious payloads. Plainbit's independent forensic analysis of one watering-hole incident revealed a process where attackers mapped internet-facing systems, compromised a website, installed a webshell, and injected JavaScript into a news article page. When a targeted user visited the compromised page, the vulnerable AnySign4PC software would generate an error and create a malicious DLL, facilitating the backdoor installation.
Further analysis by S2W identified three distinct malware clusters exhibiting patterns of DLL side-loading, encrypted registry blobs, and in-memory Portable Executable loading. Two of these clusters deployed different versions of the SIGNBT backdoor, while a third loader was observed decrypting an external payload that researchers could not fully recover. The connection to the Gunra ransomware, while noted, was not definitively attributed to the same actor, with AhnLab suggesting possibilities ranging from collaboration to shared tools or infrastructure.
The attackers employed a multi-stage approach to move laterally within compromised networks. After establishing a backdoor, they utilized privilege-escalation exploits, credential-harvesting tools like Mimikatz, Remote Desktop Protocol connections, and brute-force tools such as NLBrute to gain deeper access. The campaign's sophistication and the use of trusted domestic websites as infection vectors underscore the evolving tactics of state-sponsored threat actors targeting critical infrastructure and sensitive data in South Korea.
This incident serves as a stark reminder of the persistent threat posed by supply-chain attacks and the importance of timely patching and robust security practices for widely used software. The exploitation of a zero-day flaw in AnySign4PC, as identified by ENKI Whitehat, further emphasizes the need for proactive security measures and rapid response to emerging vulnerabilities, especially when trusted software is involved.