Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts
Reported exploitedAnySign4PCfinancial-security software AOur summary
South Korean authorities and multiple security firms have revealed a state-sponsored cyber campaign that leveraged hacked domestic websites to exploit vulnerabilities in locally installed financial-security software, including AnySign4PC. The attackers successfully deployed backdoors like SIGNBT and COPPERHEDGE without requiring any user interaction or download prompts. KISA has confirmed that AnySign4PC versions 1.1.4.4 through 1.1.4.6 are vulnerable, with version 1.1.5.0 being the patched release. AhnLab identified two other unnamed financial-security products as targets but did not disclose their specific versions or CVE identifiers. This incident highlights the growing threat of sophisticated, unpatched exploits being actively used against critical infrastructure.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.