North Korea's Lazarus Group exploits AnySign4PC in global cyber campaign
South Korean authorities and cybersecurity firms warned that the North Korean Lazarus Group has been using the mandatory financial‑security application AnySign4PC to launch zero‑day attacks. By exploiting a buffer‑overflow vulnerability, the attackers deliver malicious DLL backdoors through specially crafted PNG files and WebSockets, compromising dozens of organizations worldwide. The operation, dubbed “Operation Double Barrel,” also leverages compromised South Korean websites as watering‑hole infection points.
In a coordinated international statement, Germany, the United States, Canada, Japan, South Korea and several EU states issued a public warning about North Korean IT specialists who pose as foreign nationals to obtain remote work, funnel earnings to the regime and facilitate data theft, cryptocurrency robbery and other cyber‑crimes. The declaration cites UN Security Council resolution 2397, urging tighter identity verification and monitoring of online platforms to curb the threat.
Entities: AnySign4PC · Korea Internet & Security Agency (KISA) · Lazarus Group · North Korea · South Korea