South Korean authorities and security researchers disclosed a watering-hole campaign that compromised at least 15 legitimate domestic websites and abused vulnerable AnySign4PC software to install the SIGNBT and COPPERHEDGE backdoors on visitors' systems without user prompts. KISA said versions 1.1.4.4 through 1.1.4.6 were affected by a buffer-overflow flaw enabling remote code execution, with 1.1.5.0 identified as the patched release. Investigators said the activity ran from the second half of 2025 into 2026 and found related targeting across 72 organizations.
Technical reporting from ENKI, AhnLab, and other researchers described exploit chains in which malicious JavaScript on hacked sites used WebSocket communication with local security software, executed shellcode, injected into legitimate Microsoft processes, stored encrypted data in the registry, and loaded payloads directly in memory. Separate analysis tied the malware cluster to SIGNBT and highlighted overlap with some Gunra ransomware intrusions, including shared infrastructure, filenames, exploit paths, and anti-forensic behavior, but the current advisory stopped short of formally attributing the broader campaign or the ransomware activity to the same operator.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
An Enki blog post analyzing the joint South Korean advisory revealed three malware chains used in the watering-hole campaign, including multi-stage loaders, in-memory execution, encrypted payloads, and hidden storage in the registry and NTFS alternate data streams. It also detailed a COPPERHEDGE variant's persistence, anti-analysis techniques, and HTTP/HTTPS command-and-control via compromised South Korean web servers.
South Korean security and intelligence agencies issued a joint advisory warning that users could be infected by simply visiting compromised legitimate websites if vulnerable Korean financial-security software was installed. AhnLab described the related activity as "Operation Double Barrel" and reported strong technical overlaps between Lazarus espionage activity and the Gunra ransomware operation, while stopping short of saying both were the same actor.
The same campaign continued into 2026, with evidence of related attacks affecting 72 organizations and 15 legitimate websites used as watering holes. Security firms documented exploit chains involving malicious JavaScript, WebSocket abuse of local security software, shellcode execution, process injection, and in-memory payload loading.
Researchers observed a state-sponsored watering-hole and phishing campaign targeting visitors to trusted South Korean websites in the second half of 2025. The activity used compromised domestic sites to exploit local financial-security software and deliver the SIGNBT or COPPERHEDGE backdoors.
South Korean authorities and multiple security firms publicly disclosed the watering-hole campaign, its use of hacked Korean websites, and the SIGNBT/COPPERHEDGE malware cluster. Reporting also noted technical overlap with some Gunra ransomware intrusions but said the available analysis did not formally attribute the full campaign or Gunra incidents to Lazarus.
South Korea's KISA identified AnySign4PC versions 1.1.4.4 through 1.1.4.6 as vulnerable to a buffer overflow that enables remote code execution. The agency named version 1.1.5.0 as the fixed release.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourceenki.co.kr
Open sourcetherecord.media
Open sourcethehackernews.com
Open sourcebsky.app
Open sources2w.medium.com
Open sourcencsc.go.kr
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.