North Korea-Linked Hackers Booby-Trap Korean Websites to Push Backdoors via AnySign4PC Flaw
A state-sponsored crew hijacked trusted South Korean sites and abused a weakness in a widely installed banking security tool to plant SIGNBT and COPPERHEDGE malware, no click required.

Key points
- South Korean authorities and four security firms jointly disclosed a state-sponsored campaign that broke into trusted South Korean websites to infect visitors.
- The hackers abused a flaw in AnySign4PC, a financial security tool installed on millions of South Korean PCs to sign online banking transactions.
- A vulnerable machine could be infected simply by loading a booby-trapped page, no prompt or user action needed.
- The payloads are SIGNBT and COPPERHEDGE, two backdoors previously tied to the North Korea-linked Lazarus group.
- Users should update AnySign4PC immediately through their bank or brokerage login page, where the software normally refreshes itself.
South Korean authorities, working with four private security firms, have exposed a state-sponsored hacking campaign that turned trusted domestic websites into infection traps. Lazarus, the North Korean crew behind this operation, has been busy: our 3 July story traced two malicious npm packages to the same group, and the pattern here is consistent with what we've seen across those cases.
The target was AnySign4PC, a digital signing tool many South Korean banks and brokerages require customers to install so online transactions can be authorised. It runs quietly in the background on Windows.
The report, first surfaced by The Hacker News, describes a watering-hole attack: attackers plant malicious code on a legitimate site their intended victims are likely to visit, rather than sending phishing emails designed to trick someone into clicking.
How did the attack actually work?
A person with a vulnerable version of AnySign4PC only had to load a booby-trapped page. No pop-up, no download prompt, no button to click. The malicious page reached into the security software already running on the PC and used the flaw to execute the attackers' code.
Once that code ran, it fetched either SIGNBT or COPPERHEDGE. Both backdoors have been linked in past investigations to Lazarus. A backdoor is malware that gives an outsider quiet, ongoing remote access to a machine.
Software installed to make banking safer was turned into the way in. That's the uncomfortable part.
Who is at risk?
Anyone in South Korea running an outdated copy of AnySign4PC on Windows. That's a large pool, given the tool is close to mandatory for retail banking and stock trading with major domestic institutions.
The attackers didn't appear to be spraying malware at every visitor. Watering-hole operations of this type usually filter targets by IP range or region, firing the exploit only at people of interest, typically government, defence, crypto, or research staff. Ordinary customers may have been fingerprinted without being infected.
| Item | Detail |
|---|---|
| Affected software | AnySign4PC (financial signing client) |
| Delivery method | Compromised legitimate South Korean websites |
| User interaction | None required |
| Payloads | SIGNBT, COPPERHEDGE backdoors |
| Attributed to | North Korea-linked activity (per joint disclosure) |
| Disclosed by | South Korean authorities and four security vendors |
What should users do now?
Update AnySign4PC. The software normally refreshes itself when you log in to your bank or brokerage, so the simplest fix for most people is to sign in to their main financial site and let the plug-in patch itself. Restart the browser afterwards.
If you rarely use online banking, uninstall the client until you need it. Go to Windows Settings, then Apps, then remove AnySign4PC. It'll reinstall next time your bank requires it.
Corporate defenders should hunt for SIGNBT and COPPERHEDGE indicators on endpoints where AnySign4PC is deployed, and block outbound traffic to command-and-control infrastructure listed in the joint advisory. Any AnySign4PC process spawning cmd.exe or powershell.exe, or writing to user-profile directories, is suspicious until proven otherwise.
One caveat worth flagging: because the exploit fires without user interaction, standard awareness advice about not clicking strange links doesn't apply here. Patching is the only control that matters.



