State-Sponsored Actors Exploit AnySign4PC Zero-Day via Compromised Watering-Hole Sites to Deploy SIGNBT and COPPERHEDGE Backdoors — Threadlinqs Intelligence
As of 2026-07-31, State-Sponsored Actors Exploit AnySign4PC Zero-Day via Compromised Watering-Hole Sites to Deploy SIGNBT and COPPERHEDGE Backdoors is a critical-severity vulnerability threat attributed to Lazarus Group (North Korea), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 27 indicators of compromise.
Threat ID: TL-2026-1780 · Severity: CRITICAL · Status: ACTIVE · Category: VULNERABILITY
Attribution: Lazarus Group · North Korea · ESPIONAGE
A state-sponsored threat group exploited an unpatched buffer-overflow zero-day in AnySign4PC (certificate-based e-signature software, v1.1.4.4-1.1.4.6) and two undisclosed Korean financial-security
In its July 30, 2026 'Operation Double Barrel' report, AhnLab documents a state-sponsored threat group that exploited a zero-day buffer-overflow vulnerability in AnySign4PC (versions 1.1.4.4-1.1.4.6; fixed in 1.1.5.0) alongside two undisclosed Korean financial-security products AhnLab codenames 'software A' and 'software I'. No CVE identifier has been assigned as of this writing; KISA's June 1, 2026 notice references the flaw without a CVE/KVE number.
The exploit chain is delivered through 15 compromised, legitimate South Korean websites spanning news/media, healthcare, education, and manufacturing, supplemented by spear-phishing lures disguised as resumes, recruitment offers, investment material, and industry surveys. A four-PNG image sequence is used to (1) exchange cryptographic keys, (2) fingerprint the installed AnySign4PC version, (3) deliver version-specific exploit code, and (4) report execution success back to the attacker. The malicious webpage communicates with the locally-installed security software over a WebSocket, triggering the buffer overflow to execute shellcode with no download prompt or other user interaction, injecting payloads directly into legitimate Microsoft processes (svchost.exe, SyncHost.exe).
The campaign deploys two backdoors: SIGNBT (AhnLab designation 'Struggle'; versions 0.0.1, 1.2, and 3.0 observed) and COPPERHEDGE (AhnLab designation 'Brandoor'; a Manuscrypt-family RAT first publicly named by US-CERT in 2020). Both provide remote command execution, file theft, internal reconnaissance, process injection, and additional payload delivery; COPPERHEDGE additionally stores its C2 configuration in the Windows registry and, in documented prior variants, in NTFS Alternate Data Streams. Post-compromise, the actor uses Mimikatz for credential theft, RDP for lateral movement, and NLBrute for network credential brute-forcing, then tunnels access out via an SSH client renamed to the legitimate-looking SearchHost.exe over a reverse tunnel to 176.65.128[.]26. Anti-forensic cleanup uses SDelete and CCleaner, random four-character filename renaming, and in-memory decryption of later stages.
AhnLab links this operation to a March 9, 2026 Gunra ransomware intrusion against a South Korean healthcare organization: both intrusions share the same 'software A' vulnerability, the same compromised healthcare watering-hole site, SyncHost.exe code injection, the net.tmp/inet.tmp staging filenames, the jshosting[.]me exploit-distribution domain, the 176.65.128[.]26 reverse-tunnel address, and an identical SSH host-key fingerprint (Qr1to32lQHxEu6phzNyrTZrU0iElrOfVWMBLnqoen24). AhnLab assesses this as a 'likely technical link' rather than confirmed common operatorship, citing possible shared infrastructure, a common access broker, or limited collaboration between the state actor and the Gunra ransomware-as-a-service operation. Multiple compromised watering-hole sites also trace to a single shared web development/management vendor, which AhnLab flags as a 'possible supply-chain route' without confirmed evidence of source-code or update-pipeline compromise.
Attribution: the July 30, 2026 report itself characterizes the actor only as 'state-sponsored,' issued jointly by South Korea's NIS, NPA, KISA, and Financial Security Institute. However, AhnLab separately attributed a distinct March 2026 AnySign4PC watering-hole intrusion to Lazarus Group in an April 2026 report, and Kaspersky's Operation SyncHole research (Securelist, June 6 2025; disclosed April 2025) previously documented Lazarus using the identical SIGNBT and COPPERHEDGE malware families in watering-hole attacks against South Korean financial-security software (Cross EX, Innorix Agent) targeting IT, financial, semiconductor, and telecom firms between November 2024 and February 2025. That prior campaign used a decoy domain (smartmanagerex[.]com) impersonating a security-software vendor and a re-registered legitimate domain (thek-portal[.]com) for C2, alongside compa
Weaknesses (CWE)
CWE-120, CWE-787
Target sectors: financial services, health, education, news - media, manufacturing, information technology, semi-conductors, telecoms
Target regions: south korea
Detections & IOCs
As of 2026-08-17, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 27 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, T1608, T1583, T1584, T1189, T1566, T1203, T1059, T1218, T1543, T1574