Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts
State-sponsored attackers exploited a zero-day vulnerability in AnySign4PC (versions 1.1.4.4–1.1.4.6) to install SIGNBT or COPPERHEDGE backdoors without user interaction via compromised Korean websites. The attack chain used WebSocket communication, PNG-based key exchange, buffer overflow exploits, and process injection into legitimate Microsoft binaries like svchost.exe and SyncHost.exe. Evidence overlaps with Gunra ransomware attacks suggest shared infrastructure and techniques, though operato
Analysis
TL;DR
- State-sponsored attackers exploited a zero-day vulnerability in AnySign4PC (versions 1.1.4.4–1.1.4.6) to install SIGNBT or COPPERHEDGE backdoors without user interaction via compromised Korean websites.
- The attack chain used WebSocket communication, PNG-based key exchange, buffer overflow exploits, and process injection into legitimate Microsoft binaries like svchost.exe and SyncHost.exe.
- Evidence overlaps with Gunra ransomware attacks suggest shared infrastructure and techniques, though operator identity remains unconfirmed; victims included 72 organizations across multiple sectors.
Why It Matters
This incident highlights the critical risk posed by trusted financial-security software being weaponized against its own users through supply-side compromises. It underscores the importance of securing not just endpoints but also the integrity of widely deployed enterprise tools and the need for continuous monitoring of watering-hole campaigns targeting specific geographic or industrial sectors.
Technical Details
- Vulnerability: Zero-day in AnySign4PC (v1.1.4.4–1.1.4.6), patched in v1.1.5.0; allows remote code execution upon visiting a malicious page without prompts or downloads.
- Exploit Chain: Four PNG images used for cryptographic key exchange and version detection; WebSocket-triggered buffer overflow delivers shellcode that injects into svchost.exe or SyncHost.exe.
- Backdoors: Struggle (SIGNBT 3.0) and Brandoor (COPPERHEDGE) support RCE, file theft, reconnaissance, DLL side-loading, encrypted registry blobs, and in-memory PE loading.
- Infrastructure: Shared SSH fingerprint (Qr1to32lQHxEu6phzNyrTZrU0iElrOfVWMBLnqoen24), reverse tunnel IP (176.65.128[.]26), domain jshosting[.]me, and filenames net.tmp/inet.tmp reused across campaigns.
- Anti-Forensics: Malicious files renamed to random 4-character names, deleted via SDelete and CCleaner; evidence destruction observed during post-exploitation.
Industry Insight
Organizations must audit all installed security software—even those deemed trustworthy—for known vulnerabilities and enforce strict patch management policies. Additionally, network defenders should monitor for anomalous WebSocket traffic from web browsers to local services and detect unusual process injections into system binaries as indicators of similar supply-chain compromise tactics.
Disclaimer: The above content is generated by AI and is for reference only.