Threat reportVulnerabilityTL-2026-1780

State-Sponsored Actors Exploit AnySign4PC Zero-Day via Compromised Watering-Hole Sites to Deploy SIGNBT and COPPERHEDGE Backdoors

criticalACTIVE

State-Sponsored Actors Exploit AnySign4PC Zero-Day via (TL-2026-1780), also tracked as Operation Double Barrel, is a critical-severity software vulnerability, first published 2026-07-31. It is attributed to Lazarus Group (North Korea) with medium confidence, affects Unknown (Korean certificate-based e-signature software developer), maps to 31 MITRE ATT&CK techniques (T1003, T1005, T1018), and is covered by 9 detection rules and 27 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
0None referenced
Techniques
31MITRE ATT&CK
Actors
1Lazarus Group
Detection rules
9SPL · KQL · Sigma
IOCs
27Indicators of compromise

Key facts for TL-2026-1780

Threat ID
TL-2026-1780
Also known as
Operation Double Barrel
Severity
CRITICAL
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution
Lazarus Group
Attribution confidence
MEDIUM
Nation-state nexus
North Korea
Motivation
ESPIONAGE
Target sectors
financial services, health, education, news - media, manufacturing, information technology, semi-conductors, telecoms
Target regions
south korea
Detection rules
9
Indicators of compromise
27

Malware and tooling in State-Sponsored Actors Exploit AnySign4PC Zero-Day via

Malware and tooling: Bankshot, PostNapTea, ThreatNeedle - S0665, wAgentTea, Agamemnon downloader, CCleaner, Mimikatz, NLBrute, SDelete - S0195

How State-Sponsored Actors Exploit AnySign4PC Zero-Day via works

A state-sponsored threat group exploited an unpatched buffer-overflow zero-day in AnySign4PC (certificate-based e-signature software, v1.1.4.4-1.1.4.6) and two undisclosed Korean financial-security products, delivered via 15 compromised South Korean watering-hole sites, to silently drop SIGNBT and COPPERHEDGE backdoors on 72 organizations from H2 2025 through June 2026. AhnLab's 'Operation Double Barrel' report ties the campaign's malware, SSH key fingerprint, and network infrastructure to a March 2026 Gunra ransomware intrusion, and the malware families/TTPs match Lazarus Group's documented 'Operation SyncHole' watering-hole playbook against South Korean financial-security software.

In its July 30, 2026 'Operation Double Barrel' report, AhnLab documents a state-sponsored threat group that exploited a zero-day buffer-overflow vulnerability in AnySign4PC (versions 1.1.4.4-1.1.4.6; fixed in 1.1.5.0) alongside two undisclosed Korean financial-security products AhnLab codenames 'software A' and 'software I'. No CVE identifier has been assigned as of this writing; KISA's June 1, 2026 notice references the flaw without a CVE/KVE number.

The exploit chain is delivered through 15 compromised, legitimate South Korean websites spanning news/media, healthcare, education, and manufacturing, supplemented by spear-phishing lures disguised as resumes, recruitment offers, investment material, and industry surveys. A four-PNG image sequence is used to (1) exchange cryptographic keys, (2) fingerprint the installed AnySign4PC version, (3) deliver version-specific exploit code, and (4) report execution success back to the attacker. The malicious webpage communicates with the locally-installed security software over a WebSocket, triggering the buffer overflow to execute shellcode with no download prompt or other user interaction, injecting payloads directly into legitimate Microsoft processes (svchost.exe, SyncHost.exe).

The campaign deploys two backdoors: SIGNBT (AhnLab designation 'Struggle'; versions 0.0.1, 1.2, and 3.0 observed) and COPPERHEDGE (AhnLab designation 'Brandoor'; a Manuscrypt-family RAT first publicly named by US-CERT in 2020). Both provide remote command execution, file theft, internal reconnaissance, process injection, and additional payload delivery; COPPERHEDGE additionally stores its C2 configuration in the Windows registry and, in documented prior variants, in NTFS Alternate Data Streams. Post-compromise, the actor uses Mimikatz for credential theft, RDP for lateral movement, and NLBrute for network credential brute-forcing, then tunnels access out via an SSH client renamed to the legitimate-looking SearchHost.exe over a reverse tunnel to 176.65.128[.]26. Anti-forensic cleanup uses SDelete and CCleaner, random four-character filename renaming, and in-memory decryption of later stages.

AhnLab links this operation to a March 9, 2026 Gunra ransomware intrusion against a South Korean healthcare organization: both intrusions share the same 'software A' vulnerability, the same compromised healthcare watering-hole site, SyncHost.exe code injection, the net.tmp/inet.tmp staging filenames, the jshosting[.]me exploit-distribution domain, the 176.65.128[.]26 reverse-tunnel address, and an identical SSH host-key fingerprint (Qr1to32lQHxEu6phzNyrTZrU0iElrOfVWMBLnqoen24). AhnLab assesses this as a 'likely technical link' rather than confirmed common operatorship, citing possible shared infrastructure, a common access broker, or limited collaboration between the state actor and the Gunra ransomware-as-a-service operation. Multiple compromised watering-hole sites also trace to a single shared web development/management vendor, which AhnLab flags as a 'possible supply-chain route' without confirmed evidence of source-code or update-pipeline compromise.

Attribution: the July 30, 2026 report itself characterizes the actor only as 'state-sponsored,' issued jointly by South Korea's NIS, NPA, KISA, and Financial Security Institute. However, AhnLab separately attributed a distinct March 2026 AnySign4PC watering-hole intrusion to Lazarus Group in an April 2026 report, and Kaspersky's Operation SyncHole research (Securelist, June 6 2025; disclosed April 2025) previously documented Lazarus using the identical SIGNBT and COPPERHEDGE malware families in watering-hole attacks against South Korean financial-security software (Cross EX, Innorix Agent) targeting IT, financial, semiconductor, and telecom firms between November 2024 and February 2025. That prior campaign used a decoy domain (smartmanagerex[.]com) impersonating a security-software vendor and a re-registered legitimate domain (thek-portal[.]com) for C2, alongside companion tools ThreatNeedle, wAgent, Agamemnon downloader, and LPEClient. The malware-family and TTP overlap constitutes strong but not formally confirmed evidence that Operation Double Barrel is a continuation of Lazarus Group's established South Korean watering-hole/financial-security-software playbook.

MITRE ATT&CK techniques used in TL-2026-1780

Credential Access

T1003 OS Credential Dumping; T1056 Input Capture; T1110 Brute Force

Collection

T1005 Data from Local System

Discovery

T1018 Remote System Discovery; T1082 System Information Discovery; T1087 Account Discovery

Lateral Movement

T1021 Remote Services; T1570 Lateral Tool Transfer

Defense Evasion

T1027 Obfuscated Files or Information; T1055 Process Injection; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information; T1574 Hijack Execution Flow; T1620 Reflective Code Loading

Exfiltration

T1041 Exfiltration Over C2 Channel

Privilege Escalation

T1055 Process Injection; T1548 Abuse Elevation Control Mechanism

Execution

T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution

Command and Control

T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1573 Encrypted Channel

defense-impairment

T1112 Modify Registry

Initial Access

T1189 Drive-by Compromise; T1566 Phishing

stealth

T1218 System Binary Proxy Execution; T1574 Hijack Execution Flow

Persistence

T1543 Create or Modify System Process; T1547 Boot or Logon Autostart Execution

Resource Development

T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1608 Stage Capabilities

Affected products and versions in State-Sponsored Actors Exploit AnySign4PC Zero-Day via

  • Unknown (Korean certificate-based e-signature software developer) — AnySign4PC
    Vulnerable versions: 1.1.4.4; 1.1.4.5; 1.1.4.6
    Fixed in: 1.1.5.0
  • Undisclosed (AhnLab codename 'software A') — Financial Security Software A
    Vulnerable versions: undisclosed
    Fixed in: undisclosed
  • Undisclosed (AhnLab codename 'software I') — Financial Security Software I
    Vulnerable versions: undisclosed
    Fixed in: undisclosed

Remediation for State-Sponsored Actors Exploit AnySign4PC Zero-Day via

Patches

  • AnySign4PC 1.1.5.0 (fixes the buffer overflow present in versions 1.1.4.4-1.1.4.6).
  • Vendor patches for AhnLab-designated 'financial security software A' and 'software I' are pending; vendor identities and fixed versions are undisclosed as of July 30, 2026.

Immediate actions

  • Upgrade AnySign4PC to version 1.1.5.0 or later on all endpoints immediately.
  • Block network indicators 176.65.128[.]26 and jshosting[.]me at perimeter firewall/proxy.
  • Hunt for svchost.exe or SyncHost.exe processes with anomalous injected memory regions or unexpected outbound connections.
  • Search endpoints for net.tmp, inet.tmp, and unexplained SearchHost.exe binaries (SSH client masquerade) and random four-character-named files.
  • Audit for encrypted C2 configuration artifacts stored in the Windows registry or in NTFS Alternate Data Streams (e.g. brndlog.txt:loginfo).

Workarounds

  • Where AnySign4PC cannot be updated immediately, restrict or disable its local WebSocket listener/browser interface.
  • Restrict outbound RDP and SSH from workstations running vulnerable financial-security software.
  • Block or closely monitor traffic to recently re-registered domains masquerading as security-software vendors.

Longer-term hardening

  • Deploy EDR with behavioral detection tuned for process injection into legitimate Microsoft processes.
  • Implement application allowlisting/isolation for certificate-signature and other mandatory financial-security software to reduce watering-hole client-exploitation exposure.
  • Monitor for reuse of SSH host-key fingerprint Qr1to32lQHxEu6phzNyrTZrU0iElrOfVWMBLnqoen24 across the environment and partner networks.
  • Enforce credential hygiene (LAPS, tiered administration, MFA on RDP) to blunt Mimikatz- and NLBrute-driven lateral movement.
  • Review the shared web development/management vendor behind the compromised watering-hole sites for supply-chain exposure.

Weaknesses (CWE) in State-Sponsored Actors Exploit AnySign4PC Zero-Day via

CWE-120, CWE-787

Timeline of State-Sponsored Actors Exploit AnySign4PC Zero-Day via

  • Related Lazarus Group campaign (Operation SyncHole, documented by Kaspersky) begins exploiting Cross EX and Innorix Agent against South Korean software, IT, financial, semiconductor, and telecom firms using the same SIGNBT and COPPERHEDGE malware families later observed in Operation Double Barrel (incidents concentrated November 2024-February 2025).
  • thek-portal[.]com, a previously legitimate South Korean insurance-company domain, is re-registered for use as Lazarus C2 infrastructure in the related Operation SyncHole campaign.
  • Kaspersky GReAT publicly discloses Operation SyncHole, attributing the SIGNBT/COPPERHEDGE watering-hole campaign against South Korean supply chains to Lazarus Group.
  • Kaspersky publishes the full Securelist technical writeup of Operation SyncHole with malware analysis and IOCs.
  • Operation Double Barrel campaign begins (approximate; AhnLab reports second half of 2025): the state-sponsored actor starts exploiting the AnySign4PC zero-day and two undisclosed financial-security products via compromised South Korean watering-hole websites.
  • A distinct AnySign4PC watering-hole attack is observed in March 2026; AhnLab attributes this intrusion to Lazarus Group in a subsequent April 2026 report.
  • Gunra ransomware operators compromise 5 South Korean businesses using the same 'financial security software A' vulnerability, the same compromised healthcare watering-hole site, SyncHost.exe code injection, net.tmp/inet.tmp filenames, and the same SSH key fingerprint and reverse-tunnel address later tied to the state-sponsored actor.
  • AhnLab publishes an April 2026 report formally attributing the March 2026 AnySign4PC watering-hole attack to Lazarus Group, establishing the TTP/malware-family link relied on for Operation Double Barrel attribution.
  • KISA issues a June 1, 2026 security notice identifying AnySign4PC versions 1.1.4.4-1.1.4.6 as vulnerable to a buffer-overflow RCE flaw, with 1.1.5.0 as the fixed version; no CVE identifier is assigned.
  • Observed exploitation activity for Operation Double Barrel extends through June 2026 per AhnLab's July 2026 report, affecting 72 organizations.
  • The Hacker News and other outlets publish public coverage of the AnySign4PC watering-hole campaign, summarizing the AhnLab and joint-agency findings.
  • South Korea's NIS, NPA, KISA, and Financial Security Institute issue a joint cybersecurity advisory on Operation Double Barrel, documenting the relationship between the state-sponsored actor and the Gunra ransomware group.
  • AhnLab publishes the 'Operation Double Barrel' threat intelligence report detailing the AnySign4PC exploit chain, SIGNBT/COPPERHEDGE deployment, 15 compromised watering-hole sites, and the Gunra ransomware infrastructure overlap.

Sources cited for State-Sponsored Actors Exploit AnySign4PC Zero-Day via

Detection coverage for TL-2026-1780

As of 2026-07-31, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1780 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
27 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats