South Korean authorities and security researchers have identified a state-sponsored operation targeting visitors through compromised domestic websites. The campaign leverages vulnerabilities in AnySign4PC, a widely deployed financial-security application, to silently install SIGNBT or COPPERHEDGE backdoors on victim systems.

Attackers compromised trusted South Korean websites and injected malicious code that exploits AnySign4PC during browsing sessions. The vulnerability allows remote code execution without user interaction or prompts, meaning victims remain unaware of infection. The backdoors grant attackers persistent access to compromised machines, enabling data theft, lateral movement, and espionage activities.

AnySign4PC serves critical functions in Korean financial infrastructure and government sectors. The software handles digital signatures, authentication, and encrypted communications. Its local installation and deep system integration make it an attractive attack vector for state actors seeking reliable persistence mechanisms.

The campaign targets individuals and organizations within South Korea's financial and public sectors. Four security firms corroborated the findings, indicating the operation achieved measurable success across multiple victims. The use of locally trusted websites amplifies infection rates since users lower their guard when visiting domestic, reputable domains.

Attackers identified as state-sponsored operators likely conducted reconnaissance to identify high-value targets, then coordinated website compromises with precision exploitation. This layered approach, combining initial access via trusted platforms with zero-interaction exploitation, reflects sophisticated adversary capabilities.

Organizations using AnySign4PC must update immediately to patched versions. System administrators should implement network-level controls blocking malicious domains and monitor for SIGNBT or COPPERHEDGE command-and-control activity. Users should assume any browsing between vulnerability disclosure and patch deployment represents exposure risk.

The campaign underscores broader threats facing South Korean digital infrastructure. State actors continue targeting financial and government systems through supply-chain compromises and locally relevant software vulnerabilities. Defenders