Security · 1h ago
Hackers Exploit AnySign4PC via Compromised Korean Sites to Install Backdoors
A state-sponsored campaign compromised trusted South Korean websites to exploit a vulnerability in AnySign4PC, a financial security tool. Visitors to infected pages had SIGNBT or COPPERHEDGE backdoors installed without any prompt. The attack targeted systems running vulnerable versions of the software, leveraging the trusted sites for silent infection.
Meridian48 take
This attack highlights the danger of relying on locally installed security software that itself becomes a vector when its vulnerabilities are exploited through trusted channels.
Read the full reporting
Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts →
The Hacker News
supply-chain-attackany-sign4pc