AhnLab said it identified evidence of related attacks at 72 organizations in 2026 — many traced to legitimate South Korean websites that had been secretly altered to weaponize locally installed security software.
How AnySign4PC was abused without a download prompt
South Korean authorities and four security firms reported a state-sponsored watering‑hole campaign that exploited locally installed financial‑security software to deliver backdoors without any user prompt. The Korea Internet & Security Agency (KISA) says AnySign4PC versions 1.1.4.4 through 1.1.4.6 are vulnerable to a buffer‑overflow remote‑code execution flaw and lists version 1.1.5.0 as the fixed release; KISA recommends deleting vulnerable installations.
ENKI Whitehat said attackers exploited a zero‑day in AnySign4PC and observed activity from the second half of 2025, before KISA’s June 2026 patch notice. According to AhnLab’s Operation Double Barrel analysis, the exploit chain used four PNG images to exchange keys, check installed software version, deliver version‑specific exploit code, and report execution status. The malicious page communicated with the local security program over WebSocket, triggered a buffer overflow to execute shellcode, and caused the vulnerable security program to generate an error and create a malicious DLL without a download prompt or other user interaction.
SIGNBT (Struggle) and COPPERHEDGE (Brandoor): what the intruders installed
After successful exploitation the operators injected payloads into legitimate Microsoft processes. AhnLab reported that the attackers installed Struggle (mapped to SIGNBT 3.0) or Brandoor (AhnLab’s name for the COPPERHEDGE backdoor). The malware families supported remote command execution, file theft, internal reconnaissance, process injection, and delivery of additional payloads. S2W found recurring patterns across three clusters — DLL side‑loading, encrypted registry blobs, and in‑memory Portable Executable loading — with two clusters deploying SIGNBT versions 0.0.1 and 1.2 while a third loader decrypted an unrecoverable external payload.
ENKI observed that a Type 1 backdoor deleted its registry configuration, loader, and backdoor files from disk when running in certain modes with self‑protection enabled, leaving later stages only in memory until a clean shutdown restored files under different hashes. Plainbit’s reconstruction showed later stages decrypted in memory, code injected into svchost.exe, and command‑and‑control information read from the Windows registry — behaviour that makes behavioural telemetry more useful than static file indicators.
Overlap with Gunra ransomware and shared infrastructure
AhnLab found technical overlaps between the espionage campaign and a March 2026 Gunra ransomware intrusion. Both operations used the same compromised healthcare website and the same vulnerability in the product AhnLab calls financial‑security software A; both chains then injected code into SyncHost.exe. AhnLab stopped short of concluding the same operator controlled both operations, but listed shared elements: the filenames net.tmp and inet.tmp (with identical inet.tmp argument and similarly formatted net.tmp GUID arguments), the same SSH public‑key fingerprint Qr1to32lQHxEu6phzNyrTZrU0iElrOfVWMBLnqoen24, the reverse‑tunnelling address 176.65.128[.]26, and the domain jshosting[.]me for exploit script distribution.
The malware operators used anti‑forensic procedures in both sets of attacks, renaming malicious files to random four‑character names before deleting them; Plainbit also observed use of SDelete and CCleaner. AhnLab said the overlaps indicate a likely technical link — shared tools, infrastructure, or access paths — but do not establish who operated each intrusion. S2W said Gunra operates as a ransomware‑as‑a‑service program and reported 32 affected companies as of March 9, 2026, including five South Korean businesses.
Findings and guidance from KISA, AhnLab, ENKI Whitehat, S2W and Plainbit
The joint advisory was issued by KISA, the National Intelligence Service, the National Police Agency, and the Financial Security Institute, with analysis contributed by AhnLab, S2W, ENKI Whitehat, and Plainbit. The reports collectively recommend hunting for and preserving evidence of key behaviours: suspicious DLL loading by legitimate executables; encrypted data stored under service‑registry entries; in‑memory PE execution; unusual service creation; injection into SyncHost.exe or svchost.exe; and unexpected outbound SSH tunnels.
Plainbit documented a persistence chain in which a scheduled task named RuntimeBroker launched task.vbs, which then ran a renamed SSH client as SearchHost.exe to establish a reverse tunnel. S2W advises preserving process memory, command lines, registry values, DLL‑load events, and network records before terminating processes or isolating systems. KISA’s June 1 notice did not list a CVE identifier for the AnySign4PC flaw; The Hacker News’ search of public CVE and NVD records on July 30, 2026 found only CVE‑2020‑7882 for AnySign4PC, an unrelated older directory‑traversal issue, which does not rule out a reserved or unpublished identifier.
What this means for technologists, procurement leaders, and end users
- Technologists and security teams: hunt for behavioural indicators named above (DLL side‑loading, encrypted registry blobs, in‑memory PE), preserve volatile evidence when investigating, and remove or upgrade AnySign4PC installations identified as versions 1.1.4.4–1.1.4.6 to mitigate the reported buffer‑overflow risk.
- Procurement and IT asset owners: inventory web‑facing and internally installed certificate‑based signing tools; KISA specifically recommends deleting vulnerable AnySign4PC installations and investigators noted several compromised websites were linked to the same development and management company, a potential supply‑chain route to examine.
- End users and administrators at visited sites: be wary of spear‑phishing lures that the reports say were used — resumes, recruitment contacts, investment material, and industry surveys — and treat unexpected errors from local security programs as high‑risk symptoms rather than routine glitches.
The public record shows a technically sophisticated watering‑hole capability that weaponized trusted local signing software to place memory‑only backdoors and establish stealthy tunnels. Authorities and researchers have mapped much of the chain — from PNG images exchanging keys to in‑memory stage decryption and reverse SSH — but the relationship between the espionage activity and parallel ransomware misuse of the same access path remains unresolved. As KISA recommends, the immediate, concrete step is deletion or upgrading of vulnerable AnySign4PC installations and active hunting for the behavioural artefacts described by the investigators.
https://thehackernews.com/2026/07/hackers-exploit-anysign4pc-via-hacked.html




