Executive Summary
A sophisticated cyber campaign has been identified targeting the South Korean financial sector and related industries through the exploitation of a critical vulnerability in AnySign4PC, a widely deployed certificate-based electronic signature solution developed by HancomWITH (formerly Dream Security). Threat actors, with strong attribution to the Lazarus Group (a North Korean state-sponsored APT), leveraged compromised legitimate Korean websites to deliver drive-by exploits. These attacks enabled the silent installation of advanced backdoors and malware on victim systems without any user prompts or interaction. The exploitation chain capitalized on a zero-day vulnerability in AnySign4PC (versions 1.1.4.4 through 1.1.4.6), allowing remote code execution (RCE) and persistent compromise. This report provides a comprehensive technical analysis of the attack, threat actor profile, observed tactics, techniques, and procedures (TTPs), victimology, and actionable mitigation strategies.
Threat Actor Profile
The primary threat actor behind this campaign is the Lazarus Group, also tracked as HIDDEN COBRA, Labyrinth Chollima, ZINC, NICKEL ACADEMY, and Diamond Sleet. This group is notorious for its advanced persistent threat (APT) operations, specializing in cyber-espionage, financial theft, and disruptive attacks. Lazarus has a long history of targeting South Korean entities, particularly in the financial, government, and critical infrastructure sectors. Their operations are characterized by multi-stage attack chains, custom malware development, and the use of both phishing and watering hole techniques. The group is known for leveraging zero-day vulnerabilities, sophisticated lateral movement, and data exfiltration capabilities, often culminating in ransomware or double extortion scenarios.
Technical Analysis of Malware/TTPs
The attack chain begins with the compromise of legitimate Korean websites, including those in the news, healthcare, education, and manufacturing sectors. Malicious JavaScript is injected into these sites, which, upon being visited by a user with a vulnerable version of AnySign4PC, initiates a drive-by exploit. The exploit communicates with the local AnySign4PC process via WebSocket, checks the installed version, and delivers a version-specific payload embedded in PNG images. This payload triggers a buffer overflow in AnySign4PC, resulting in the execution of attacker-controlled shellcode.
The shellcode injects advanced malware such as SIGNBT (versions 3.0, 0.0.1, 1.2) and COPPERHEDGE (also known as Brandoor) into legitimate Windows processes like svchost.exe and SyncHost.exe. These backdoors provide the attackers with remote command execution, file theft, process injection, internal reconnaissance, and the ability to deliver additional payloads. Persistence is achieved through scheduled tasks (e.g., RuntimeBroker launching task.vbs), registry-based configuration, DLL side-loading, and in-memory PE execution. The attackers also deploy credential theft tools such as Mimikatz and NLBrute, and establish outbound SSH tunnels for command and control (C2) communications.
Notably, the exploit chain does not require any user interaction or download prompt, making detection and prevention significantly more challenging. The attackers have demonstrated the ability to move laterally within compromised networks, escalate privileges, and exfiltrate sensitive data. In some cases, ransomware such as Gunra has been deployed as a final stage, with data exfiltration and double extortion tactics observed.
Key indicators of compromise (IOCs) include SSH public-key fingerprints (e.g., Qr1to32lQHxEu6phzNyrTZrU0iElrOfVWMBLnqoen24), reverse-tunneling addresses (e.g., 176.65.128[.]26), malicious domains (e.g., jshosting[.]me), and malware filenames such as net.tmp and inet.tmp. Process injection targets include svchost.exe and SyncHost.exe, with evidence of encrypted registry blobs and unusual DLL loading activity.
Exploitation in the Wild
The campaign has been active since at least early 2026, with a significant uptick in activity observed in 2026. At least 72 organizations have been confirmed affected, with over 15 legitimate Korean websites used as watering holes for malware distribution. The primary victims are in the South Korean financial sector, including banks, investment firms, and fintech companies, but global financial institutions have also been impacted. Large databases from compromised organizations have been exfiltrated and sold on dark web forums, and several incidents have escalated to ransomware deployment and double extortion, with stolen data published on leak sites.
The attackers have demonstrated continuous use of compromised distribution sites, rotating infrastructure and payloads to evade detection. The overlap of infrastructure and techniques with other campaigns, such as those involving Gunra ransomware, suggests a high level of operational sophistication and resource sharing among North Korean threat actors.
Victimology and Targeting
The primary targets of this campaign are organizations within the South Korean financial sector, including banks, securities firms, insurance companies, and fintech providers. Secondary targets include entities in the healthcare, education, and manufacturing sectors, as well as global financial institutions with ties to South Korea. The attackers have shown a preference for high-value targets with access to sensitive financial data and critical infrastructure. The use of watering hole attacks via trusted websites increases the likelihood of compromising users with elevated privileges or access to sensitive systems.
Victims are typically infected without any awareness, as the exploit chain requires no user interaction. The attackers prioritize persistence and stealth, often remaining undetected for extended periods while conducting internal reconnaissance, credential harvesting, and data exfiltration. The campaign has resulted in significant financial losses, reputational damage, and regulatory scrutiny for affected organizations.
Mitigation and Countermeasures
Immediate action is required to mitigate the risk posed by this campaign. Organizations should delete all instances of AnySign4PC versions 1.1.4.4, 1.1.4.5, and 1.1.4.6 from their endpoints and upgrade to version 1.1.5.0 or later, which addresses the exploited vulnerability. Security teams should actively hunt for behavioral indicators such as suspicious DLL loading, encrypted registry blobs, in-memory PE execution, unusual service creation, process injection into svchost.exe or SyncHost.exe, and outbound SSH tunnels.
Network and endpoint monitoring should be configured to detect connections to known malicious domains and IP addresses associated with this campaign. Incident response procedures should include the preservation of process memory, command lines, registry values, DLL-load events, and network records prior to system isolation. Organizations are advised to conduct comprehensive threat hunting for Lazarus Group TTPs, leveraging frameworks such as MITRE ATT&CK for detection and response.
User awareness training should emphasize the risks associated with visiting untrusted websites, even those that appear legitimate. Regular vulnerability assessments and patch management are critical to reducing the attack surface. Collaboration with industry peers and threat intelligence providers can enhance situational awareness and facilitate rapid response to emerging threats.
References
AhnLab ASEC: March 2026 Security Issues in the Korean & Global Financial Sector
The Hacker News: Hackers Exploit AnySign4PC via Hacked Korean Sites
KISA Security Notice, June 2026
About Rescana
Rescana is a leader in third-party risk management (TPRM), providing organizations with advanced tools to identify, assess, and mitigate cyber risks across their digital supply chain. Our platform leverages real-time threat intelligence, automated risk scoring, and continuous monitoring to empower security teams with actionable insights and proactive defense capabilities. For more information or to discuss how Rescana can help secure your organization, please contact us at info@rescana.com.



