🟠 High  |  Source: The Hacker News


A state-sponsored threat actor compromised legitimate South Korean websites to silently exploit a vulnerability in AnySign4PC, a widely deployed financial security plugin. Victims visiting the tampered sites were infected with SIGNBT or COPPERHEDGE backdoors without any user interaction or prompts. The campaign highlights the danger of watering-hole attacks targeting locally mandated software with privileged system access.

Security Architect’s Take: Audit your organisation’s estate for mandated endpoint security or financial software such as AnySign4PC, particularly in South Korea-operating environments, and ensure patching is current. Enforce browser isolation or application allowlisting to reduce exposure to watering-hole delivery mechanisms, and verify that any locally trusted plugins cannot be silently invoked by arbitrary web content.

Original advisory: Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts