# State-Sponsored Actors Exploit AnySign4PC Zero-Day via Compromised Watering-Hole Sites to Deploy SIGNBT and COPPERHEDGE Backdoors

> A state-sponsored threat group exploited an unpatched buffer-overflow zero-day in AnySign4PC (certificate-based e-signature software, v1.1.4.4-1.1.4.6) and two undisclosed Korean financial-security products, delivered via 15 compromised South Korean watering-hole sites, to silently drop SIGNBT and COPPERHEDGE backdoors on 72 organizations from H2 2025 through June 2026. AhnLab's 'Operation Double Barrel' report ties the campaign's malware, SSH key fingerprint, and network infrastructure to a March 2026 Gunra ransomware intrusion, and the malware families/TTPs match Lazarus Group's documented 'Operation SyncHole' watering-hole playbook against South Korean financial-security software.

- **Published:** 2026-07-31T00:00:00Z
- **Last reviewed:** 2026-07-31T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1780
- **ID:** TL-2026-1780
- **Severity:** CRITICAL
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Actor:** Lazarus Group (North Korea)
- **Detections:** 9 · **IOCs:** 27 (full data via the Threadlinqs MCP server — Purple tier)

## Description

In its July 30, 2026 'Operation Double Barrel' report, AhnLab documents a state-sponsored threat group that exploited a zero-day buffer-overflow vulnerability in AnySign4PC (versions 1.1.4.4-1.1.4.6; fixed in 1.1.5.0) alongside two undisclosed Korean financial-security products AhnLab codenames 'software A' and 'software I'. No CVE identifier has been assigned as of this writing; KISA's June 1, 2026 notice references the flaw without a CVE/KVE number.

The exploit chain is delivered through 15 compromised, legitimate South Korean websites spanning news/media, healthcare, education, and manufacturing, supplemented by spear-phishing lures disguised as resumes, recruitment offers, investment material, and industry surveys. A four-PNG image sequence is used to (1) exchange cryptographic keys, (2) fingerprint the installed AnySign4PC version, (3) deliver version-specific exploit code, and (4) report execution success back to the attacker. The malicious webpage communicates with the locally-installed security software over a WebSocket, triggering the buffer overflow to execute shellcode with no download prompt or other user interaction, injecting payloads directly into legitimate Microsoft processes (svchost.exe, SyncHost.exe).

The campaign deploys two backdoors: SIGNBT (AhnLab designation 'Struggle'; versions 0.0.1, 1.2, and 3.0 observed) and COPPERHEDGE (AhnLab designation 'Brandoor'; a Manuscrypt-family RAT first publicly named by US-CERT in 2020). Both provide remote command execution, file theft, internal reconnaissance, process injection, and additional payload delivery; COPPERHEDGE additionally stores its C2 configuration in the Windows registry and, in documented prior variants, in NTFS Alternate Data Streams. Post-compromise, the actor uses Mimikatz for credential theft, RDP for lateral movement, and NLBrute for network credential brute-forcing, then tunnels access out via an SSH client renamed to the legitimate-looking SearchHost.exe over a reverse tunnel to 176.65.128[.]26. Anti-forensic cleanup uses SDelete and CCleaner, random four-character filename renaming, and in-memory decryption of later stages.

AhnLab links this operation to a March 9, 2026 Gunra ransomware intrusion against a South Korean healthcare organization: both intrusions share the same 'software A' vulnerability, the same compromised healthcare watering-hole site, SyncHost.exe code injection, the net.tmp/inet.tmp staging filenames, the jshosting[.]me exploit-distribution domain, the 176.65.128[.]26 reverse-tunnel address, and an identical SSH host-key fingerprint (Qr1to32lQHxEu6phzNyrTZrU0iElrOfVWMBLnqoen24). AhnLab assesses this as a 'likely technical link' rather than confirmed common operatorship, citing possible shared infrastructure, a common access broker, or limited collaboration between the state actor and the Gunra ransomware-as-a-service operation. Multiple compromised watering-hole sites also trace to a single shared web development/management vendor, which AhnLab flags as a 'possible supply-chain route' without confirmed evidence of source-code or update-pipeline compromise.

Attribution: the July 30, 2026 report itself characterizes the actor only as 'state-sponsored,' issued jointly by South Korea's NIS, NPA, KISA, and Financial Security Institute. However, AhnLab separately attributed a distinct March 2026 AnySign4PC watering-hole intrusion to Lazarus Group in an April 2026 report, and Kaspersky's Operation SyncHole research (Securelist, June 6 2025; disclosed April 2025) previously documented Lazarus using the identical SIGNBT and COPPERHEDGE malware families in watering-hole attacks against South Korean financial-security software (Cross EX, Innorix Agent) targeting IT, financial, semiconductor, and telecom firms between November 2024 and February 2025. That prior campaign used a decoy domain (smartmanagerex[.]com) impersonating a security-software vendor and a re-registered legitimate domain (thek-portal[.]com) for C2, alongside companion tools ThreatNeedle, wAgent, Agamemnon downloader, and LPEClient. The malware-family and TTP overlap constitutes strong but not formally confirmed evidence that Operation Double Barrel is a continuation of Lazarus Group's established South Korean watering-hole/financial-security-software playbook.

## MITRE ATT&CK

- T1608 Stage Capabilities
- T1583 Acquire Infrastructure
- T1584 Compromise Infrastructure
- T1189 Drive-by Compromise
- T1566 Phishing
- T1203 Exploitation for Client Execution
- T1059 Command and Scripting Interpreter
- T1218 System Binary Proxy Execution
- T1543 Create or Modify System Process
- T1574 Hijack Execution Flow
- T1547 Boot or Logon Autostart Execution
- T1055 Process Injection
- T1548 Abuse Elevation Control Mechanism
- T1055 Process Injection
- T1574 Hijack Execution Flow
- T1027 Obfuscated Files or Information
- T1070 Indicator Removal
- T1620 Reflective Code Loading
- T1112 Modify Registry
- T1140 Deobfuscate/Decode Files or Information
- T1003 OS Credential Dumping
- T1110 Brute Force
- T1056 Input Capture
- T1087 Account Discovery
- T1082 System Information Discovery
- T1018 Remote System Discovery
- T1021 Remote Services
- T1570 Lateral Tool Transfer
- T1005 Data from Local System
- T1071 Application Layer Protocol
- T1573 Encrypted Channel
- T1105 Ingress Tool Transfer
- T1041 Exfiltration Over C2 Channel

## Sources

- [Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts](https://thehackernews.com/2026/07/hackers-exploit-anysign4pc-via-hacked.html)
- [AhnLab Operation Double Barrel (ENG) - AhnLab Cyber Threat Intelligence Report](https://image.ahnlab.com/atip/content/file/20260730/[AhnLab]Operation%20Double%20Barrel(ENG)(2026.07.30).pdf)
- [Joint Cybersecurity Advisory: Operation Double Barrel (State-Sponsored Actor / Gunra Ransomware Relationship)](https://www.hendryadrian.com/joint-cybersecurity-advisory-operation-double-barrel-the-relationship-between-a-state-sponsored-threat-actor-and-the-gunra-ransomware-group/)
- [KISA Security Notice - State-Sponsored Hacking Group Attacks](https://www.boho.or.kr/kr/bbs/view.do?bbsId=B0000133&menuNo=205020&nttId=72144)
- [Operation SyncHole: Lazarus APT goes back to the well](https://securelist.com/operation-synchole-watering-hole-attacks-by-lazarus/116326/)
- [Operation SyncHole: Lazarus APT targets supply chains in South Korea](https://securityaffairs.com/176964/apt/operation-synchole-lazarus-apt-targets-supply-chains-in-south-korea.html)
- [South Korean Companies Targeted by Lazarus via Watering Hole Attacks, Zero-Days](https://www.securityweek.com/south-korean-companies-targeted-by-lazarus-via-watering-hole-attacks-zero-days/)
- [Lazarus Group, Labyrinth Chollima, HIDDEN COBRA, Guardians of Peace, ZINC, NICKEL ACADEMY, Diamond Sleet (G0032)](https://attack.mitre.org/groups/G0032/)
- [State Hackers Made South Korea's Mandatory Banking Software Into Zero-Day Weapon](https://www.techtimes.com/articles/322157/20260730/state-hackers-made-south-koreas-mandatory-banking-software-zero-day-weapon.htm)
- [Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts (syndicated)](https://nuclearcoffee.org/hackers-exploit-anysign4pc-via-hacked-korean-sites-to-install-backdoors-without-prompts/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1780
