Connect with us

Security

Uncovering the Dangerous Tactics of Cybercriminals: Backdoor Installations via Hacked Korean Sites

Published

on

Recommended Actions:

  • Delete vulnerable installations of AnySign4PC versions 1.1.4.4 through 1.1.4.6.
  • Update to fixed release version 1.1.5.0.
  • Be cautious of spear-phishing messages disguised as various types of content.
  • Avoid visiting compromised websites, especially in the finance, healthcare, education, and manufacturing sectors.
  • Monitor for signs of compromise, such as unusual network activity or unexpected file changes.
  • Implement strong cybersecurity measures, including regular software updates and employee training on cybersecurity best practices.

By following these recommendations, organizations can better protect themselves against state-sponsored cyber threats and minimize the risk of falling victim to malicious attacks.

Enhanced Security Measures Recommended for Vulnerable Installations

Version 1.1.5.0 has been identified as the fixed release, with recommendations to remove vulnerable installations to prevent security breaches.

Identification of Suspicious Activities by ENKI

Reports indicate that ENKI discovered a Type 1 backdoor that deleted its registry configuration, loader, and backdoor files to evade detection. This backdoor operates in modes 1, 2, 4, or 5 with self-protection enabled, ensuring that the files remain absent from disk until a clean shutdown restores them. The altered hash of the loader emphasizes the importance of behavioral telemetry over stable-file indicators for detection.

Persistence Chain Analysis by Plainbit

Plainbit observed a persistence chain involving a scheduled task named RuntimeBroker launching task.vbs, which then executed a renamed SSH client as SearchHost.exe to establish a reverse tunnel. S2W recommends capturing process memory, command lines, registry values, DLL-load events, and network records before terminating processes or isolating systems for further investigation.

Possible Supply-Chain Compromise Identified by AhnLab

AhnLab discovered that several compromised websites were linked to the same development and management company, suggesting a potential supply-chain infiltration. While there is no evidence of compromise to the company’s source code, software-update process, or central management platform, caution is advised for potential risks associated with the connection.

Update on AnySign4PC Vulnerability

KISA’s recent notice regarding the AnySign4PC flaw does not include a CVE identifier. The Hacker News search conducted on July 30, 2026, only revealed CVE-2020-7882, an unrelated directory-traversal vulnerability affecting older versions of AnySign4PC. This discrepancy highlights the possibility of a reserved, unpublished, or differently described identifier for the vulnerability. AhnLab’s report also mentions unidentified software A and I, without specifying their affected or fixed versions.

See also  Pwn2Own Ireland: Hackers Unleash 34 Zero-Day Exploits on Opening Day

Trending