
Fake Resumes + Watering Holes Hit AnySign4PC Users
A state-sponsored campaign in South Korea used spear-phishing and hacked “trusted” local websites to infect visitors who had vulnerable AnySign4PC installed.…
South Korean agencies and AhnLab warn that tools tied to North Korea’s Lazarus Group appear to be shared with the Gunra ransomware operation targeting South Korean organizations. The campaign used compromised legitimate websites (watering-hole attacks) and spearphishing emails, including messages disguised as a semiconductor survey, to trigger flaws in widely used Korean financial security software and deliver malicious code.
According to AhnLab and South Korean agencies, tools associated with the Lazarus Group appear to have been shared with the Gunra ransomware operation, with both running parallel campaigns against South Korean targets between 2025 and the first half of 2026. Their goals differed: espionage in one case, ransomware extortion in the other, but the delivery methods overlapped.
One track used spearphishing. A Korean defense company received emails disguised as a survey about GaN semiconductors, pushing recipients toward a lure page. AhnLab noted that some of these lure pages appeared to have been generated with AI, making them harder to distinguish from a genuine survey request.
The second track relied on watering-hole attacks. Attackers compromised 15 legitimate Korean websites across multiple industries and used them to redirect selected visitors to infrastructure that triggered flaws in widely used Korean financial security software, injecting malicious code into legitimate Microsoft processes. AhnLab assessed that attackers likely compromised a hosting provider or development company's management system to expand this access across many client sites at once.
The Korean financial security software involved is described as effectively mandatory for banking and government services, meaning a large population of users had it installed and were exposed to the same vulnerabilities. Because the flaws could be triggered simply by loading a specific page, infection did not require the victim to open a file or approve any prompt, and outdated security software increased the risk further. The survey pretext also exploited a routine, low-suspicion business activity, an industry or academic survey request, to reach a defense-adjacent audience.
Organizations should keep endpoint and financial security software fully patched, since some infections in this campaign occurred simply from browsing to a compromised legitimate site. Employees, especially in finance, defense, engineering, and IT roles, should be encouraged to verify unexpected survey or research requests before clicking any link. IT and security teams should treat unexpected redirects on known sites as a reportable event rather than a minor annoyance, since watering-hole infrastructure can affect general user environments running vulnerable software, not just explicitly targeted organizations.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
They sent spearphishing emails disguised as a survey about GaN semiconductors, aiming to get recipients to click a link to a lure page.
Yes. The advisory warns that visiting a compromised legitimate site can trigger infection, especially if the visitor has outdated security software installed.
Attackers compromised 15 legitimate Korean websites across multiple industries and used them to redirect selected visitors to infrastructure that triggered software flaws and injected malicious code.
AhnLab reported that Lazarus and Gunra ran parallel campaigns against South Korean targets with different end goals, espionage versus ransomware extortion, while apparently sharing some tools.
In Korea, just opening the wrong “GaN semiconductor survey” email can end in ransomware on your PC. Lazarus-linked tools and Gunra ransomware ran side by side, using that fake survey and even normal Korean websites, watering-hole style, to hit mandatory banking security software. Here’s the nasty part: you can be infected just by visiting a compromised Korean site. The page silently redirects, triggers an old security plug-in, and slips code into normal Microsoft processes. If you get a GaN semiconductor survey email or see a trusted Korean site suddenly redirect, stop. Don’t click further, capture a screenshot and call our security team immediately.

A state-sponsored campaign in South Korea used spear-phishing and hacked “trusted” local websites to infect visitors who had vulnerable AnySign4PC installed.…

This threat trend report describes multiple real-world APT campaigns that rely on social engineering (job offers, fake recruiters, code reviews, and…

Cisco Talos Incident Response reports that phishing drove initial access in over half of Q2 2026 cases, often using QR codes in PDF attachments and trusted…

A Russian-linked group allegedly stole sensitive contact data from the Netherlands National Police after getting access to an employee’s email account. The…

Investigators found an exposed WebDAV server being used as a “malware delivery lab” with over 1,000 files for testing lures, filenames, and execution tricks.…

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…