North Korea-Linked Hackers Booby-Trap Korean Websites to Push Backdoors via AnySign4PC Flaw
A state-sponsored crew hijacked trusted South Korean sites and abused a weakness in a widely installed banking security tool to plant SIGNBT and COPPERHEDGE malware, no click required.

Key points
- South Korean authorities and four security firms have jointly disclosed a state-sponsored campaign that broke into trusted South Korean websites to infect visitors.
- The hackers abused a flaw in AnySign4PC, a financial security tool installed on millions of South Korean PCs to sign online banking transactions.
- A vulnerable machine could be infected simply by loading a booby-trapped page, with no prompt or user click needed.
- The payloads are SIGNBT and COPPERHEDGE, two backdoors previously tied to the North Korea-linked Lazarus group.
- Users should update AnySign4PC immediately through their bank or brokerage login page, which is where the software normally refreshes itself.
South Korean authorities, working with four private security firms, have exposed a state-sponsored hacking campaign that turned trusted South Korean websites into infection traps. The hackers used those sites to attack a piece of financial security software that sits on huge numbers of South Korean PCs, and then dropped backdoors on the machines of the people they wanted to spy on.
The target was AnySign4PC. That is a digital signing tool many South Korean banks and brokerages require customers to install so online transactions can be authorised. It runs quietly in the background on Windows.
The report, first surfaced by The Hacker News, describes a watering-hole attack. That is the industry term for when attackers plant malicious code on a legitimate site their intended victims are likely to visit, rather than sending phishing emails, which are fake messages designed to trick someone into clicking.
How did the attack actually work?
A person with a vulnerable version of AnySign4PC only had to load a booby-trapped page. There was no pop-up, no download prompt, no button to click. The malicious page reached into the security software already running on the PC and used the flaw to run the attackers' code.
Once that code ran, it fetched one of two backdoors: SIGNBT or COPPERHEDGE. Both have been linked in past investigations to Lazarus, the hacking group Western and South Korean agencies attribute to North Korea. A backdoor is malware that gives an outsider quiet, ongoing remote access to a computer.
The short version: software installed to make banking safer was turned into the way in.
Who is at risk?
Anyone in South Korea running an outdated copy of AnySign4PC on a Windows PC. That is a large pool. The tool is close to mandatory for retail banking and stock trading with major domestic institutions.
The attackers did not appear to be spraying malware at everyone who visited the hacked sites. Watering-hole operations of this type usually filter targets by IP address, browser, or region, and only fire the exploit at people of interest (typically government, defence, crypto, or research staff). Ordinary customers may have been fingerprinted without being infected.
| Item | Detail |
|---|---|
| Affected software | AnySign4PC (financial signing client) |
| Delivery method | Compromised legitimate South Korean websites |
| User interaction | None required |
| Payloads | SIGNBT, COPPERHEDGE backdoors |
| Attributed to | North Korea-linked activity (per joint disclosure) |
| Disclosed by | South Korean authorities and four security vendors |
What should users do now?
Update AnySign4PC. The software normally refreshes itself when you log in to your bank or brokerage, so the simplest fix for most people is to sign in to their main financial site and let the security plug-in patch itself. Restart the browser afterwards.
If you rarely use online banking, uninstall the client until you need it. Windows Settings, Apps, then remove AnySign4PC. It will reinstall next time your bank asks for it.
Corporate defenders should hunt for SIGNBT and COPPERHEDGE indicators on endpoints where AnySign4PC is deployed, and block outbound traffic to command-and-control infrastructure listed in the joint advisory. Treat any AnySign4PC process spawning cmd.exe, powershell.exe, or writing to user-profile directories as suspicious until proven otherwise.
One caveat worth flagging: because the exploit fires without user interaction, standard user-awareness advice (do not click strange links) does not help here. Patching is the control that matters.



