Trusted Korean Pages Became Endpoint Compromise Paths
A trusted website is enough here. A visit to a compromised Korean page could silently trigger malware on a machine with vulnerable AnySign4PC installed, so the helper app becomes an immediate endpoint compromise path instead of a narrow certificate issue.
KISA says AnySign4PC versions 1.1.4.4 through 1.1.4.6 are affected and lists 1.1.5.0 as the fixed release. The attack installs SIGNBT or COPPERHEDGE without a download prompt or other obvious user action, which is why standard web filtering and “don’t download files” controls miss it.
For any environment that uses browser-bridging signing or certificate helper software, the risk is the software already on the endpoint, not the page content alone. A page visit can be enough to hand attackers the machine.