CVE Tools
Back to feed
Exploited in the wild AnySign4PC web-app financial-security software A malware

Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts

The Hacker News·By The Hacker News··6 min read
CVE Tools coverage

South Korean authorities and multiple security firms have revealed a state-sponsored cyber campaign that leveraged hacked domestic websites to exploit vulnerabilities in locally installed financial-security software, including AnySign4PC. The attackers successfully deployed backdoors like SIGNBT and COPPERHEDGE without requiring any user interaction or download prompts. KISA has confirmed that AnySign4PC versions 1.1.4.4 through 1.1.4.6 are vulnerable, with version 1.1.5.0 being the patched release. AhnLab identified two other unnamed financial-security products as targets but did not disclose their specific versions or CVE identifiers. This incident highlights the growing threat of sophisticated, unpatched exploits being actively used against critical infrastructure.