A state-sponsored campaign has been uncovered, where hackers compromised trusted South Korean websites to exploit vulnerabilities in locally installed financial-security software, specifically AnySign4PC. This allowed attackers to install backdoors, including SIGNBT or COPPERHEDGE, on targeted systems without prompting the user. The compromised websites were used to deliver the malware, enabling the attackers to gain unauthorized access to sensitive information. The campaign's use of trusted websites to spread malware increases the likelihood of successful infections, as users are more likely to trust content from familiar sources1. The fact that this is a state-sponsored campaign raises the stakes, as the implications extend beyond the immediate target and into the realm of geopolitics. This matters to security practitioners because state-aligned threat activity can have far-reaching consequences, making it essential to stay vigilant and prioritize the security of sensitive systems.