INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
North Korea's Lazarus Group Exploits AnySign4PC
| 2026-07-30 14:00 CRITICAL HIGHExecutive Summary AI-generated
The North Korean Lazarus Group has been linked to a ransomware scheme, with the group sharing tools and infrastructure with hackers targeting South Korean organizations. The Lazarus Group exploited vulnerabilities in Korean financial security software products, installing espionage backdoors that have encrypted files, stolen data, and demanded extortion payments. Spearphishing campaigns were also launched against targeted sectors, including government agencies, cryptocurrency exchanges, and IT service providers. This is not the first time North Korean actors have been linked to ransomware operations; previous investigations have revealed similar connections between Pyongyang-backed hackers and various malware payloads.
Technical Mitigations AI-generated
* Use up-to-date and patched versions of operating systems, browsers, and software to reduce the risk of exploitation by known vulnerabilities.
* Implement robust security measures such as multi-factor authentication, encryption, and secure password storage to protect against unauthorized access.
* Regularly update and patch firmware and device drivers to ensure that any installed software is protected from known exploits.
* Use a reputable antivirus solution and keep it up-to-date with the latest signatures and definitions.
* Conduct regular system scans and malware removals to detect and remove any potential threats, including backdoors and ransomware.
Technical Observables
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation SyncHoleOperation SyncHoleOperation Double BarrelOperation Double Barrel
AndarielAndarielLazarus GroupLazarus Group
ContiContiQilinQilin
CVE-2020-7882CVE-2020-7882
Target & Sectors
DPRK
DPRK
governmentgovernment
healthcarehealthcare
defensedefense
manufacturingmanufacturing
educationeducation
Incident Timeline
April 2025
North Korea's Lazarus Group shared Conti v2 source code with ransomware hackers targeting South Korean companies.
Click on any entity below to view its context and source!
target_region
Korea, Republic of
Gunra emerged in April 2025, initially targeting five South Korean companies.
the second half of 2025
North Korea's Lazarus Group shared ransomware tools with the incident.
March 9, 2026
North Korea's Lazarus Group shared ransomware tools with Conti-derived malware hackers.
Click on any entity below to view its context and source!
tactic
Ransomware
The firm said the operation had affected 32 companies as of March 9, 2026, including five South Korean businesses, and had moved from Conti-derived ransomware to its own Windows and Linux builds.
target_region
Korea, Republic of
The firm said the operation had affected 32 companies as of March 9, 2026, including five South Korean businesses, and had moved from Conti-derived ransomware to its own Windows and Linux builds.
malware
Conti
The firm said the operation had affected 32 companies as of March 9, 2026, including five South Korean businesses, and had moved from Conti-derived ransomware to its own Windows and Linux builds.
infrastructure
Windows
The firm said the operation had affected 32 companies as of March 9, 2026, including five South Korean businesses, and had moved from Conti-derived ransomware to its own Windows and Linux builds.
infrastructure
Linux
The firm said the operation had affected 32 companies as of March 9, 2026, including five South Korean businesses, and had moved from Conti-derived ransomware to its own Windows and Linux builds.
general_metric
32 companies
The firm said the operation had affected 32 companies as of March 9, 2026, including five South Korean businesses, and had moved from Conti-derived ransomware to its own Windows and Linux builds.
March 2026
North Korea's Lazarus Group shared tools with ransomware hackers through the Gunra Trail, targeting healthcare and manufacturing sectors.
Click on any entity below to view its context and source!
industry
Healthcare
As of March 2026, the group had claimed at least 32 victims globally across healthcare, manufacturing, IT, and other sectors.
The Gunra Trail
A March 2026
Gunra ransomware
intrusion used the same compromised healthcare website and the same vulnerability in the product AhnLab calls financial-security software A. Both the state-sponsored and ransomware chains then injected code into SyncHost.exe.
industry
Manufacturing
As of March 2026, the group had claimed at least 32 victims globally across healthcare, manufacturing, IT, and other sectors.
victims
32 victims
As of March 2026, the group had claimed at least 32 victims globally across healthcare, manufacturing, IT, and other sectors.
tactic
Ransomware
The Gunra Trail
A March 2026
Gunra ransomware
intrusion used the same compromised healthcare website and the same vulnerability in the product AhnLab calls financial-security software A. Both the state-sponsored and ransomware chains then injected code into SyncHost.exe.
observable
SyncHost.exe
The Gunra Trail
A March 2026
Gunra ransomware
intrusion used the same compromised healthcare website and the same vulnerability in the product AhnLab calls financial-security software A. Both the state-sponsored and ransomware chains then injected code into SyncHost.exe.
organisation
Tor
As with many RaaS schemes, it operates a double-extortion model, stealing data before encrypting systems and threatening to publish it on a Tor-based leak site.
June 1
Threat actors used AnySign4PC versions 1.1.4.4 through 1.1.4.6 to target South Korean agencies, exploiting a buffer overflow vulnerability in the software.
Click on any entity below to view its context and source!
infrastructure
1.1.4
Patch the Software, Hunt the Behaviour
KISA's
June 1 security notice
identifies AnySign4PC versions 1.1.4.4 through 1.1.4.6 as vulnerable to a buffer overflow that permits remote code execution.
observable
1.1.4.4
Patch the Software, Hunt the Behaviour
KISA's
June 1 security notice
identifies AnySign4PC versions 1.1.4.4 through 1.1.4.6 as vulnerable to a buffer overflow that permits remote code execution.
observable
1.1.4.6
Patch the Software, Hunt the Behaviour
KISA's
June 1 security notice
identifies AnySign4PC versions 1.1.4.4 through 1.1.4.6 as vulnerable to a buffer overflow that permits remote code execution.
tactic
Buffer Overflow
Patch the Software, Hunt the Behaviour
KISA's
June 1 security notice
identifies AnySign4PC versions 1.1.4.4 through 1.1.4.6 as vulnerable to a buffer overflow that permits remote code execution.
tactic
Remote Code Execution
Patch the Software, Hunt the Behaviour
KISA's
June 1 security notice
identifies AnySign4PC versions 1.1.4.4 through 1.1.4.6 as vulnerable to a buffer overflow that permits remote code execution.
organisation
Patch the
Patch the Software, Hunt the Behaviour
KISA's
June 1 security notice
identifies AnySign4PC versions 1.1.4.4 through 1.1.4.6 as vulnerable to a buffer overflow that permits remote code execution.
tactic
T1592.002 - Software
Patch the Software, Hunt the Behaviour
KISA's
June 1 security notice
identifies AnySign4PC versions 1.1.4.4 through 1.1.4.6 as vulnerable to a buffer overflow that permits remote code execution.
organisation
CVE
The available evidence does not establish that the company's source code, software-update process, or central management platform was compromised.
KISA's June 1 notice does not list a CVE identifier for the AnySign4PC flaw.
June 2026
North Korea's Lazarus Group shared ransomware tools with the incident target, South Korean agencies warned in June 2026.
July 30, 2026
Threat actors shared North Korea's Lazarus Group tools with ransomware hackers.
Click on any entity below to view its context and source!
vulnerability
CVE-2020-7882
As of July 30, 2026, The Hacker News found only
CVE-2020-7882
in public CVE Program and NVD searches for AnySign4PC, an unrelated directory-traversal vulnerability affecting older versions.
organisation
The Hacker News
As of July 30, 2026, The Hacker News found only
CVE-2020-7882
in public CVE Program and NVD searches for AnySign4PC, an unrelated directory-traversal vulnerability affecting older versions.
organisation
CVE Program
As of July 30, 2026, The Hacker News found only
CVE-2020-7882
in public CVE Program and NVD searches for AnySign4PC, an unrelated directory-traversal vulnerability affecting older versions.
organisation
NVD
As of July 30, 2026, The Hacker News found only
CVE-2020-7882
in public CVE Program and NVD searches for AnySign4PC, an unrelated directory-traversal vulnerability affecting older versions.
2026/07/30
North Korea's Lazarus Group shared tools with ransomware hackers, compromising 72 organizations in South Korea.
Click on any entity below to view its context and source!
threat_actor
Lazarus Group
North Korea’s Lazarus Group sharing tools with ransomware hackers, South Korean agencies warn.
Cyberattack tools and infrastructure used by North Korea’s Lazarus Group appear to have been shared with ransomware criminals targeting South Korean organizations, according to new research released Thursday alongside a
joint advisory
by four South Korean security and intelligence agencies.
threat_actor
Andariel
The increasing adoption of third-party ransomware by North Korean actors came under focus back in 2024, when the U.S. Department of Justice
unsealed an indictment
against Rim Jong Hyok, an alleged member of the government’s
Andariel Unit
, for his alleged role in ransomware attacks on U.S. hospitals and healthcare companies.
victims
72 organizations
Where the Lazarus hackers have installed espionage backdoors in at least 72 organizations in 2026 alone — including government agencies, cryptocurrency exchanges, and IT service providers — Gunra has instead used its access to encrypt files, steal data and demand an extortion payment.
AhnLab said it identified evidence of related attacks at 72 organizations in 2026.
organisation
AhnLab
According to AhnLab, both groups also used identical malware filenames and execution arguments, the same privilege escalation tools, the same command-and-control servers, and the same SSH key fingerprint — a cryptographic identifier that functions like a unique digital signature.
AhnLab refers to two exploited products only as financial-security software A and I.
organisation
SSH
According to AhnLab, both groups also used identical malware filenames and execution arguments, the same privilege escalation tools, the same command-and-control servers, and the same SSH key fingerprint — a cryptographic identifier that functions like a unique digital signature.
The shared evidence included the same initial-access vulnerability, malware filenames and execution patterns, SSH key fingerprint, and network infrastructure.
organisation
Barrel
AhnLab's
Operation Double Barrel report
describes an exploit chain that used four PNG images to exchange keys, check the installed software version, deliver version-specific exploit code, and report whether execution succeeded.
organisation
PNG
AhnLab's
Operation Double Barrel report
describes an exploit chain that used four PNG images to exchange keys, check the installed software version, deliver version-specific exploit code, and report whether execution succeeded.
organisation
Microsoft
As part of their campaign, the attackers compromised 15 legitimate Korean websites across multiple industries and used them for watering-hole attacks, redirecting selected visitors of those compromised sites to specific infrastructure that triggered the software flaws and injected malicious code into legitimate Microsoft processes.
The payload was then injected into legitimate Microsoft processes.
organisation
Gunra
The Gunra connection may represent something different.
AhnLab does not identify software A, so the report does not establish that the Gunra-linked vulnerability was AnySign4PC.
organisation
PE
The reports recommend hunting for suspicious DLL loading by legitimate executables, encrypted data stored under service-registry entries, in-memory PE execution, unusual service creation, injection into SyncHost.exe or svchost.exe, and unexpected outbound SSH tunnels.
infrastructure
Windows
The resulting backdoor decrypted later stages in memory, injected code into svchost.exe, and read command-and-control information from the Windows registry.
infrastructure
1.1.4
The Korea Internet & Security Agency (KISA) says AnySign4PC versions 1.1.4.4 through 1.1.4.6 are affected and lists version 1.1.5.0 as the fixed release.
infrastructure
1.1.5
The Korea Internet & Security Agency (KISA) says AnySign4PC versions 1.1.4.4 through 1.1.4.6 are affected and lists version 1.1.5.0 as the fixed release.
The public reports do not say whether attackers continued exploiting AnySign4PC after version 1.1.5.0 became available.
It lists version 1.1.5.0 as the fixed release and recommends deleting vulnerable installations.
organisation
The Korea Internet & Security Agency
The Korea Internet & Security Agency (KISA) says AnySign4PC versions 1.1.4.4 through 1.1.4.6 are affected and lists version 1.1.5.0 as the fixed release.
organisation
KISA
The Korea Internet & Security Agency (KISA) says AnySign4PC versions 1.1.4.4 through 1.1.4.6 are affected and lists version 1.1.5.0 as the fixed release.
organisation
WebSocket
The malicious page communicated with the local security program over WebSocket and triggered a buffer overflow to execute shellcode.
organisation
NLBrute
The attackers subsequently used privilege-escalation exploits, Mimikatz and other credential tools, Remote Desktop Protocol connections, and NLBrute to move through the network.
infrastructure
0.0.1
Two clusters deployed SIGNBT versions 0.0.1 and 1.2, while a third loader decrypted an external payload that researchers could not recover.
infrastructure
1.2
Two clusters deployed SIGNBT versions 0.0.1 and 1.2, while a third loader decrypted an external payload that researchers could not recover.
organisation
GUID
The inet.tmp argument was identical, while the net.tmp arguments followed a similar GUID format.
organisation
RuntimeBroker
Plainbit observed one persistence chain in which a scheduled task named RuntimeBroker launched task.vbs, which then ran a renamed SSH client as SearchHost.exe to establish a reverse tunnel.
organisation
Hackers Exploit
Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts.
organisation
Hacked Korean Sites
Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts.
organisation
SIGNBT
The attackers used those sites to exploit locally installed financial-security software and infect targeted visitors with
SIGNBT
or
COPPERHEDGE
backdoors.
organisation
Plainbit
Whitehat, and Plainbit.
organisation
DLL
When a target visited it, the vulnerable security program generated an error and created a malicious DLL without a download prompt or other user interaction.
organisation
Qr1to32lQHxEu6phzNyrTZrU0iElrOfVWMBLnqoen24
Both operations used the same SSH public-key fingerprint Qr1to32lQHxEu6phzNyrTZrU0iElrOfVWMBLnqoen24.
organisation
SDelete
Plainbit observed additional evidence destruction using SDelete and CCleaner.
organisation
CCleaner
Plainbit observed additional evidence destruction using SDelete and CCleaner.
organisation
COPPERHEDGE
Those reports document prior Lazarus use of AnySign4PC, SIGNBT, COPPERHEDGE, and watering-hole exploitation.
Tactical Metrics
Metrics
victims
72
Organizations
Click for context!
Where the Lazarus hackers have installed espionage backdoors in at least 72 organizations in 2026 alone — including government agencies, cryptocurrency exchanges, and IT service providers — Gunra has instead used its access to encrypt files, steal data and demand an extortion payment.
AhnLab said it identified evidence of related attacks at 72 organizations in 2026.
Metrics
victims
32
Victims
As of March 2026, the group had claimed at least 32 victims globally across healthcare, manufacturing, IT, and other sectors.
Metrics
infrastructure
Windows
Affected Product
The firm said the operation had affected 32 companies as of March 9, 2026, including five South Korean businesses, and had moved from Conti-derived ransomware to its own Windows and Linux builds.
The resulting backdoor decrypted later stages in memory, injected code into svchost.exe, and read command-and-control information from the Windows registry.
Metrics
infrastructure
Linux
Affected Product
The firm said the operation had affected 32 companies as of March 9, 2026, including five South Korean businesses, and had moved from Conti-derived ransomware to its own Windows and Linux builds.
Metrics
infrastructure
1.1.4
Software Version
The Korea Internet & Security Agency (KISA) says AnySign4PC versions 1.1.4.4 through 1.1.4.6 are affected and lists version 1.1.5.0 as the fixed release.
Patch the Software, Hunt the Behaviour
KISA's
June 1 security notice
identifies AnySign4PC versions 1.1.4.4 through 1.1.4.6 as vulnerable to a buffer overflow that permits remote code execution.
Metrics
infrastructure
1.1.5
Software Version
The Korea Internet & Security Agency (KISA) says AnySign4PC versions 1.1.4.4 through 1.1.4.6 are affected and lists version 1.1.5.0 as the fixed release.
The public reports do not say whether attackers continued exploiting AnySign4PC after version 1.1.5.0 became available.
It lists version 1.1.5.0 as the fixed release and recommends deleting vulnerable installations.
Metrics
infrastructure
0.0.1
Software Version
Two clusters deployed SIGNBT versions 0.0.1 and 1.2, while a third loader decrypted an external payload that researchers could not recover.
Metrics
infrastructure
1.2
Software Version
Two clusters deployed SIGNBT versions 0.0.1 and 1.2, while a third loader decrypted an external payload that researchers could not recover.
Intelligence Sources
TheRecord
2026-07-30
The Hacker News
2026-07-30
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Reset / Delete
Incident Version History
CURRENT VERSION
Last Updated: 2026-08-03T12:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
28x
organisation
Identified Entity
AhnLab
entity
12x
timeline
Temporal Reference
2026
date
8x
tactic
Cyber Operation Type
Ransomware
tactic
7x
attribution
Attributing Entity
Gunra
authority
5x
industry
Targeted Sector
Government
sector
4x
infrastructure
Software Version
1.1.4
version
3x
tactic
MITRE ATT&CK Technique
T1021.001 - Remote Desktop Protocol
technique
2x
target region
Target Country
Korea, Democratic People's Republic of
country
2x
threat actor
APT Group
Lazarus Group
actor
2x
malware
Malware Payload
Qilin
tool
2x
campaign
Campaign
Operation Double Barrel
operation
2x
infrastructure
Affected Product
Windows
software
Contextual Telemetry
Context Block
13 METRICS
target region
Target Region
DPRK
region
victims
Organizations
72
organizations
source region
Origin Region
DPRK
region
victims
Victims
32
victims
general metric
Legitimate Korean Websites
15
legitimate korean websites
general metric
Companies
32
companies
malware
Offensive Tool
Mimikatz
tool
general metric
Versions
1
versions
vulnerability
Exploited CVE
CVE-2020-7882
cve
source region
Origin Country
Korea, Republic of
country
general metric
Signbt
3
signbt
general metric
Type
1
type
general metric
Modes
5
modes
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.