A joint advisory says compromised South Korean websites exploited vulnerable AnySign4PC versions in a state-sponsored campaign, while security firms also found a technical overlap with a Gunra ransomware intrusion.
South Korean authorities and private security firms have detailed a state-sponsored watering hole campaign that exploited a buffer overflow in AnySign4PC, a widely installed security program used for online banking and government services, allowing victims to be infected simply by visiting compromised news, hospital and other legitimate websites. The joint advisory and related security reports said 15 South Korean websites were compromised and linked the activity to attacks at 72 organizations across 2025 and into 2026. KISA said vulnerable AnySign4PC versions 1.1.4.4 through 1.1.4.6 were patched in version 1.1.5.0, while researchers said active exploitation dates back to the second half of 2025, leaving a gap of at least six months before the June 1, 2026 security notice. AhnLab separately attributed a March 2026 AnySign4PC watering hole attack to Lazarus, and the malware used in the broader campaign — SIGNBT and COPPERHEDGE — has previously been associated with the North Korea-backed group. Security firms said attackers compromised legitimate websites, planted malicious JavaScript into real pages and used a WebSocket connection to the locally running software to trigger remote code execution with no prompt or download. The resulting malware was injected into legitimate Microsoft processes including SyncHost.exe and svchost.exe, with encrypted command-and-control data stored in the Windows registry. Investigators said the intrusions were later used for credential theft, lateral movement and broader network compromise. AhnLab also found a March 2026 Gunra ransomware intrusion at a South Korean healthcare organization that used the same vulnerability, the same compromised healthcare website, the same SyncHost.exe injection technique, the same SSH key fingerprint, and matching network infrastructure. The firm called that a likely technical link but stopped short of saying the espionage and ransomware operations were run by the same actor. The findings add to a longer pattern of Lazarus exploiting South Korea’s mandatory client-side security software, following earlier campaigns involving Cross EX in 2025 and MagicLine4NX in 2023.