AnySign4PC zero-day exploited as entry point: 72 South Korean organizations hit, same channel used by Gunra ransomware
AnySign4PC zero-day exploited 72 South Korean organizations via clickless infection, sharing infrastructure with Gunra ransomware attacks.
Illustrative image generated with AI
From site visit to clickless infection
The mechanism was as simple as it was silent. Landing on one of the compromised pages — fifteen legitimate South Korean websites used as watering holes — was enough to receive malicious code with no prompt, download or click. The attack exploited a zero-day vulnerability in the certified electronic signature software AnySign4PC, a widely used product in South Korea for signing digital documents. Vulnerable versions range from 1.1.4.4 to 1.1.4.6; the patch was released by KISA in June 2026 with version 1.1.5.0.
Activity was observed starting in the second half of 2025 and intensified in 2026. Campaigns combined spear-phishing and the compromise of trusted sites, enabling in‑memory shellcode execution and the injection of payloads into legitimate Microsoft processes like svchost.exe and SyncHost.exe.
The backdoors that took control
Two malware strains were implanted on the reached systems: SIGNBT (also known as Struggle, versions 0.0.1, 1.2 and 3.0) and COPPERHEDGE (alias Brandoor). Both featured full command-and-control capabilities: remote command execution, selective file theft, internal network reconnaissance, process injection and the loading of additional payloads.
Lateral movement leveraged privilege escalation exploits, Mimikatz, RDP and NLBrute, while evidence removal relied on legitimate utilities like SDelete and CCleaner. AhnLab identified compromise evidence in 72 organizations in 2026, spanning healthcare, education, manufacturing, media and other sectors.
The shadow of Gunra ransomware
A troubling detail concerns the infrastructure shared with the Gunra ransomware attack, observed in March 2026. It has not been proven that the operators are the same, but the overlapping elements are numerous:
- The same South Korean healthcare website, previously compromised, was used as a bridge for both campaigns.
- The identical vulnerability was exploited on a financial security product that AhnLab calls “financial software A”.
- Temporary files like
net.tmpandinet.tmp, the SSH key fingerprint used for remote access, the reverse-tunneling infrastructure and the domain hosting offensive scripts (jshosting[.]me) match perfectly.
This sharing suggests a common initial access, possibly brokered, and makes it plausible that organizations already visited by the cyber‑espionage group may end up targeted by a subsequent ransomware attack.
Two financial software still unpatched
Beyond AnySign4PC, AhnLab reported that the same condition was exploited on two additional financial security products, designated “A” and “I”, whose identities and exact versions have not been disclosed. To date, no public patches exist for these two pieces of software. KISA has issued a single clear instruction: immediately delete AnySign4PC versions from 1.1.4.4 to 1.1.4.6 and update to 1.1.5.0.
The activity was jointly reconstructed by KISA, the National Intelligence Service, the National Police Agency, the Financial Security Institute and the security companies AhnLab, S2W, ENKI Whitehat and Plainbit. Attribution remains to an unnamed state‑sponsored group.
Sources
This article is an original reworking based on the sources below.




