Operation Double Barrel state-sponsored watering-hole campaign targeting South Korean visitors
Campaign
Summary
Hide ▲
Show ▼
A state-sponsored watering-hole campaign compromised trusted South Korean websites and used them to deliver SIGNBT or COPPERHEDGE backdoors to targeted visitors. The operation, identified as Operation Double Barrel, ran from the second half of 2025 through July 2026 and relied on malicious pages that exploited locally installed financial-security software without user interaction.
Related Happenings
North American cryptocurrency company hit by network compromise
Incident
H score31
First: 28.04.2026 11:00
Last: 28.04.2026 11:00
Sources 1
About this happening:
A North American cryptocurrency company suffered a multi-stage intrusion that began on January 23, 2026, and the attackers kept access for 66 days. The foothold ca...
North American cryptocurrency company hit by network compromise
IncidentAbout this happening: A North American cryptocurrency company suffered a multi-stage intrusion that began on January 23, 2026, and the attackers kept access for 66 days. The foothold ca...
Timeline
-
30.07.2026 13:33 1 articles · 2h ago
KISA flags AnySign4PC buffer overflow and fixed release 1.1.5.0
Initial DisclosureSouth Korean authorities and security firms disclosed a state-sponsored campaign that compromised trusted domestic websites and used them to exploit locally installed AnySign4PC versions 1.1.4.4 through 1.1.4.6, silently install SIGNBT or COPPERHEDGE backdoors, and direct defenders to delete vulnerable installations and move to version 1.1.5.0.
Show sources
- Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts — thehackernews.com — 30.07.2026 13:33