Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts
A state-sponsored threat group, potentially linked to Lazarus and operating between 2025 and 2026, exploited vulnerabilities in AnySign4PC, a certificate-based electronic signature software, to install backdoors on targeted websites. These websites were used as watering holes to infect visitors with SIGNBT and COPPERHEDGE backdoors. The attacks involved a complex chain of actions, including DLL side-loading, encrypted registry blobs, and in-memory PE execution, and were linked to the Gunra ransomware operation. While attribution to Lazarus remains inconclusive, evidence suggests a strong technical link and potential collaboration.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
