The record
Written from the 1 report below. Nothing here is unsourced.
- South Korean authorities and four security firms say state-sponsored hackers exploited a zero-day flaw in AnySign4PC, software used for certificate-based electronic signatures, by compromising trusted Korean websites to infect targeted visitors' computers automatically.
- Merely visiting an infected page was enough to install SIGNBT or COPPERHEDGE backdoors on machines running vulnerable versions, enabling remote control, file theft, and movement across networks.
- AhnLab found evidence of related attacks at 72 organisations and technical overlaps with Gunra ransomware attacks, though it could not confirm the same actors carried out both.
- Versions 1.1.4.4 to 1.1.4.6 are affected, and users are advised to update to version 1.1.5.0 or delete vulnerable installations.
What to watch next
- Whether attackers continue exploiting AnySign4PC now that version 1.1.5.0 is available.
- Whether the identities of 'financial-security software A and I' and their affected versions are disclosed.
- What authorities conclude about the relationship between the state-sponsored campaign and the Gunra ransomware operators.
Coverage1
1 report
English national1
All filed from India
Named South Korea · AnySign4PC · COPPERHEDGE · SIGNBT · AhnLab · ENKI Whitehat · Financial Security Institute · Kaspersky · Korea Internet & Security Agency · Lazarus · National Intelligence Service · National Police Agency · Plainbit
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
