A joint South Korean government advisory has exposed a state-sponsored operation that weaponized trusted domestic websites to silently infect visitors, exploiting vulnerabilities in locally installed financial security software to plant backdoors.
Anyone on a compromised page could be infected with no prompts or downloads, provided they ran a vulnerable AnySign4PC version. The Korea Internet and Security Agency (KISA) says versions 1.1.4.4 through 1.1.4.6 of the certificate-based signature tool are affected, with 1.1.5.0 as the fixed release, and advises deleting vulnerable installations. Its June 1 notice flags a buffer overflow enabling remote code execution.
The advisory came from KISA, the National Intelligence Service, the National Police Agency, and the Financial Security Institute, built on analysis from AhnLab, S2W, ENKI Whitehat, and Plainbit. AhnLab documented attacks at 72 organizations in 2026 and found 15 legitimate websites serving as watering holes, including news portals, hospital sites, and smaller weakly secured pages.
The campaign also used spear-phishing disguised as resumes, recruitment outreach, and investment material. AhnLab’s Operation Double Barrel report details an exploit chain that exchanged keys through four PNG images, checked the installed software version, and delivered version-specific exploit code over WebSocket, triggering a buffer overflow to run shellcode. Payloads landed inside legitimate Microsoft processes, dropping backdoors mapped to SIGNBT and COPPERHEDGE with remote command execution, file theft, and reconnaissance functions.
The advisory stops short of naming the group, and neither AhnLab nor KISA formally ties the campaign to Lazarus, though AhnLab separately attributed a March 2026 AnySign4PC watering hole attack to that group. KISA’s notice lists no CVE identifier for the flaw; only the unrelated CVE-2020-7882 appears in public searches.
