
Tax and SSA Phish Push Cruciferra Malware Loader
Researchers report multiple real-world email phishing campaigns that used tax and government-benefit themes to trick people into downloading malware. The…
A state-sponsored campaign in South Korea used spear-phishing and hacked “trusted” local websites to infect visitors who had vulnerable AnySign4PC installed. In some cases, simply visiting a compromised page triggered the exploit and installed SIGNBT or COPPERHEDGE backdoors without any download prompt. Authorities and multiple security firms say the activity affected dozens of organizations across several sectors.
This campaign combined two social engineering paths aimed at the same outcome: getting a backdoor onto a target's machine. The first path used spear-phishing messages disguised as resumes, recruitment approaches, investment material, and industry surveys, sent to specific employees, often in HR or recruiting roles who routinely open unsolicited attachments as part of their job.
The second path was a watering hole approach. Attackers compromised legitimate websites, including news, healthcare, education, and manufacturing sites, that intended victims were likely to visit during normal browsing. If a visitor's machine had a vulnerable version of AnySign4PC (versions 1.1.4.4 to 1.1.4.6) installed, simply loading the compromised page could trigger an exploit and drop a malicious DLL without any download prompt or other user interaction.
The phishing lures worked because they targeted roles whose normal job function requires opening resumes and outreach messages from strangers, making typical "don't click unknown attachments" advice hard to apply cleanly. The watering hole component removed the need for any user decision at all: no attachment to open, no link to click, just a normal visit to a site employees already trusted. That combination let attackers reach a wide range of sectors, with related activity reportedly affecting dozens of organizations across finance, media, healthcare, education, and manufacturing.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Attackers compromised legitimate news, healthcare, education, and manufacturing sites that intended victims were likely to visit. If a visitor had a vulnerable version of AnySign4PC installed, the page could trigger an exploit and install a malicious DLL without any download prompt or user action.
The attackers sent spear-phishing messages disguised as resumes, recruitment approaches, investment material, and industry surveys, primarily targeting HR and recruiting staff.
AnySign4PC versions 1.1.4.4 through 1.1.4.6 were vulnerable to exploitation through compromised web pages.
Keep endpoints patched, remove outdated or vulnerable security plug-ins, verify unsolicited recruiting or survey outreach through trusted channels, and treat unusual browser or security-software errors after normal browsing as a potential incident.
In South Korea, dozens of companies got hit just by opening a resume… or reading a normal news article. State-backed groups sent fake resumes, recruiter pitches, and industry surveys, and also hacked 15 trusted local sites. If you had vulnerable AnySign4PC, just visiting a compromised page silently installed backdoors, no download prompt, no clicks. The only clue on your side: the email is unsolicited recruiting, survey, or investment material, or your browser and security tools act weird right after visiting a trusted local site, errors, freezes, or sudden background activity. Your move: if you ever see weird AnySign4PC or browser errors right after opening a resume email or a common local site, stop using that device and report it to IT immediately.

Researchers report multiple real-world email phishing campaigns that used tax and government-benefit themes to trick people into downloading malware. The…

A June 2026 financial-sector threat report describes real phishing emails that used business-looking themes (e.g., money transfers, receipts, voicemail) to…

FortiGuard Labs reports an active phishing operation (“TTF Trap”) where emails posing as invoices, shipping documents, or business proposals deliver an archive…

Researchers reported an active PhantomEnigma campaign where attackers hijacked 20+ Brazilian government websites and used them as trusted stepping-stones to…

ClickFix is a fast-growing social engineering tactic that gets people to run malware themselves by pasting a command into Windows Run or macOS Terminal.…

This threat trend report describes multiple real-world APT campaigns that rely on social engineering (job offers, fake recruiters, code reviews, and…