Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts
Four security companies and South Korean authorities have revealed a state-sponsored effort that breached reputable domestic websites. The attackers utilized those websites to infect targeted users with SIGNBT or COPPERHEDGE backdoors and take advantage of locally installed financial security software.
Without a prompt or user-initiated download, a hacked page might infect a system running a vulnerable version of AnySign4PC. AnySign4PC versions 1.1.4.4 through 1.1.4.6 are impacted, according to the Korea Internet & Security Agency (KISA), which cites version 1.1.5.0 as the repaired release. It suggests removing installations that are susceptible.
Only two exploited items are referred to by AhnLab as financial-security software A and I. Their identities, impacted or patched versi...

