View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

State-Sponsored Hackers Exploit AnySign4PC in South Korea to Deploy

๐Ÿšจ ACTIVE EXPLOITATION

  • State-Sponsored Hackers Exploit AnySign4PC in South Korea to Deploy Backdoors CVE-... Hackers exploited AnySign4PC vulnerabilities via compromised Korean sites to install backdoors silently.

    • Targets: South Korean users of AnySign4PC financial-security software versions 1.1.4.4 to 1.1.4.6
    • Vulnerability: Buffer overflow allowing remote code execution without user prompts
    • Attack vector: Compromised trusted domestic websites used as watering holes and spear-phishing emails
    • Payloads: SIGNBT (Struggle) and COPPERHEDGE (Brandoor) backdoors enabling remote control and data theft
    • Overlap found with Gunra ransomware attacks sharing infrastructure and tactics but no confirmed single actor ๐Ÿ“Ž Coverage: thehackernews.com ยท ๐Ÿ‘ via The Hacker News
  • SilverFox Uses 3-Driver BYOVD Chain to Deploy ValleyRAT on Japanese Manufacturer SilverFox targeted a Japanese industrial manufacturer using a multi-driver BYOVD attack to deploy ValleyRAT.

    • Targets Japanese industrial manufacturing sector organizations
    • Exploits new and known vulnerable drivers in a three-driver BYOVD framework
    • Attack starts with invoice-themed phishing delivering a ZIP archive for DLL side-loading
    • Uses drivers BootRepair.sys, EnPortv.sys, and wsftprm.sys for kernel access and evasion
    • Deploys ValleyRAT (Winos 4.0) via thread-context hijacking and dual watchdog persistence ๐Ÿ“Ž Coverage: thehackernews.com ยท ๐Ÿ‘ via The Hacker News

๐Ÿ’ฅ BREACHES & INCIDENTS

  • Hackers steal 607,000 records in cyberattack on UK Department for Education Hackers accessed 607,000 records from the UK Department for Education in a cyberattack.
    • Applies to UK Department for Education and related education sector entities
    • 607,000 records including telephone numbers and email addresses were stolen
    • No bank details or highly sensitive information were accessed
    • Attack affected Turing Scheme portal and DfE online help desk services
    • Incident contained quickly; DfE working with National Cyber Security Centre and National Crime Agency ๐Ÿ“Ž Coverage: bbc.com ยท ๐Ÿ‘ via @metacurity@infosec.exchange

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • Chinese-Speaking Threat Actor Uses Autonomous AI for Multi-Vulnerability Cyberattacks A Chinese-speaking threat actor launched autonomous AI-driven cyberattacks exploiting seven vulnerabilities.

    • Targets infrastructure across 10 product families with seven prioritized vulnerabilities
    • Uses Hermes Agent framework with DeepSeek AI for autonomous vulnerability enumeration and exploitation
    • Orchestrates attacks via Telegram, combining AI-driven scanning with manual exploitation
    • Leverages multiple large language models including Qwen, GLM, Kimi, MiniMax, and tests Western tools like Claude Code and Codex
    • Employs proxy services and anti-attribution settings to evade detection and limit traceability ๐Ÿ“Ž Coverage: unit42.paloaltonetworks.com ยท ๐Ÿ“„ Original: unit42.paloaltonetworks.com ยท ๐Ÿ‘ via Palo Alto Unit 42
  • OctLurk and SilkLurk backdoors target Central Asian government organizations since 2025 Researchers discovered OctLurk and SilkLurk backdoors used in cyber-espionage campaigns in Central Asia.

    • Targets include government, healthcare, research, law enforcement, and educational sectors in Central Asia and Syria
    • Backdoors operate primarily in memory and use customized loaders with victim-specific decryption
    • Capabilities include plugin injection for shells, network scanning, credential dumping, keylogging, and email harvesting
    • Deployment involves scheduled tasks and malicious services loading obfuscated DLL loaders
    • Attribution suggests a Chinese-speaking threat actor with no confirmed group linkage ๐Ÿ“Ž Coverage: securelist.com ยท ๐Ÿ“„ Original: securelist.com ยท ๐Ÿ‘ via Securelist (Kaspersky)

๐Ÿ”“ CVEs & KEV

  • Other: 16 CVEs (worst 8.8)

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check