A state-sponsored cyberespionage campaign is actively targeting users in South Korea through a sophisticated watering hole attack. Threat actors are compromising trusted South Korean websites and using them to exploit a vulnerability in AnySign4PC, a popular financial security software. The attack is highly effective as it requires no user interaction; anyone visiting a compromised site with a vulnerable version of AnySign4PC installed can be infected. The payload consists of backdoors identified as SIGNBT and COPPERHEDGE. Security firm AhnLab has identified attacks at 72 organizations and found 15 compromised websites used in the campaign. The Korea Internet & Security Agency (KISA) has advised users to update the software immediately.
This campaign leverages a classic watering hole strategy: instead of targeting victims directly, the attackers compromise websites they are likely to visit.
Attack Chain:
T1203 - Exploitation for Client Execution.AhnLab's research also found tactical overlaps with attacks that deployed Gunra ransomware, including shared vulnerabilities and infrastructure, but a definitive link to a single threat actor has not been made.
The core of the attack is the vulnerability in AnySign4PC. While a CVE ID has not yet been assigned, it appears to be a flaw that allows for remote code execution when parsing content on a webpage. This type of vulnerability in a security product is particularly dangerous because the software is expected to be trusted and runs with elevated privileges. The use of compromised but legitimate websites makes the attack difficult for users to detect, as they are not visiting overtly malicious domains. The malware deployed, SIGNBT and COPPERHEDGE, are likely custom backdoors designed for espionage, allowing the attackers to steal files, log keystrokes, and execute further commands on the compromised systems (T1059 - Command and Scripting Interpreter).
The impact of this campaign is primarily focused on espionage and data theft from targeted organizations in South Korea. By compromising systems within these organizations, the state-sponsored actor can gain long-term access to sensitive information. The use of a vulnerability in a mandatory security software creates a large pool of potential victims. The impact on an individual victim organization could include the loss of intellectual property, sensitive government or business data, and a persistent network intrusion that is difficult to eradicate.
No specific technical Indicators of Compromise (IPs, domains, hashes) were provided in the source articles.
Security teams at organizations in South Korea should hunt for:
%TEMP%, %APPDATA%) immediately following web browsing activity.D3-PA: Process Analysis.D3-OTF: Outbound Traffic Filtering.D3-SU: Software Update.New advisory details state-backed campaign now uses spear-phishing and watering holes, targeting Naver Whale browser users and broader sectors like media, healthcare, and finance.
A joint advisory from NIS and KISA reveals the state-backed campaign targeting South Korea has expanded its tactics. In addition to watering hole attacks, the threat actor is now employing sophisticated spear-phishing, impersonating recruiters to deliver malware. The watering hole attacks show increased precision, with malicious code specifically activating for users of Naver's Whale browser. The campaign's scope is broader, impacting media, healthcare, and finance sectors, and involves injecting backdoors into legitimate Microsoft processes for defense evasion. This indicates a more extensive and sophisticated operation than previously understood.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.