MEDIUMApt
Global

Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts

·Source: The Hacker News

Updated:

Executive Summary

South Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The attackers used those sites to exploit locally installed financial-security software and infect targeted visitors with SIGNBT or COPPERHEDGE backdoors. A compromised page could infect a system running a vulnerable AnySign4PC version without a prompt or

Analysis

South Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The attackers used those sites to exploit locally installed financial-security software and infect targeted visitors with SIGNBT or COPPERHEDGE backdoors. A compromised page could infect a system running a vulnerable AnySign4PC version without a prompt or
Source Attribution

Originally published by The Hacker News on Jul 30, 2026.

Related Threats