Authorities in South Korea, along with four security firms, have uncovered a campaign by state-sponsored hackers exploiting compromised Korean websites to target users with vulnerable versions of AnySign4PC. Attackers used these sites as watering holes to deliver SIGNBT and COPPERHEDGE backdoors to unsuspecting visitors without any user intervention. The Korea Internet & Security Agency has identified AnySign4PC versions 1.1.4.4 through 1.1.4.6 as vulnerable and recommends upgrading to version 1.1.5.0 or deleting the software. Reports from AhnLab indicate that the attack was part of a larger operation affecting 72 organizations and involved 15 legitimate websites. Evidence suggests similarities with previous attacks linked to Gunra ransomware, although no definitive attribution to a single group has been made. The attackers utilized spear-phishing techniques and compromised various industry websites to reach their targets. The joint advisory issued by multiple South Korean agencies, including the National Intelligence Service and the Financial Security Institute, highlights ongoing risks from phishing and watering-hole attacks. Further analysis by firms like ENKI Whitehat and Plainbit reveals the complexity of the attack, involving zero-day vulnerabilities, buffer overflows, and intricate malware execution chains. Security teams are advised to upgrade vulnerable software, monitor for unusual DLL loading and registry activity, and strengthen defenses against remote code execution threats.