State-sponsored hackers are exploiting vulnerabilities in AnySign4PC software through compromised South Korean websites to install malicious backdoors on visitor systems [1].

This campaign represents a significant security risk because it allows attackers to gain persistent access to target machines without any user interaction. By leveraging trusted domestic websites, the actors can bypass traditional security warnings and infect systems silently.

According to reports from South Korean authorities and security firms, the attackers have targeted visitors to compromised domestic websites [1]. Once a user visits a malicious page, the exploit triggers the installation of either the SIGNBT or COPPERHEDGE backdoors [1]. These tools allow the state-sponsored actors to maintain long-term access to the infected systems for espionage, or further disruption.

The attack specifically targets a vulnerability within the AnySign4PC software, a common security tool used in South Korea. The process is efficient, as it does not require the user to click a link or download a file manually.

"A compromised page could infect a system running a vulnerable AnySign4PC version without a prompt or," the report from The Hacker News said [1].

Security researchers said that the use of state-sponsored resources allows for a more sophisticated approach to the exploitation of these vulnerabilities. The focus on domestic Korean sites suggests a targeted effort to compromise specific regional infrastructure, or personnel [1]. Authorities have urged users to update their software to the latest versions to mitigate the risk of infection.

State-sponsored hackers are exploiting vulnerabilities in AnySign4PC software through compromised South Korean websites.

The use of 'drive-by' downloads via trusted local websites indicates a shift toward high-stealth infiltration methods. By exploiting a widely used regional software like AnySign4PC, attackers can achieve a high infection rate among specific demographics in South Korea, facilitating large-scale intelligence gathering while avoiding the detection triggers associated with phishing emails.