/

July 31, 2026

The Security Software Was the Way In: One Page Visit, No Click, Full Backdoor

A joint advisory from South Korean government agencies and security firms just described one of the most unsettling attack chains we’ve covered: visitors to fifteen hijacked, completely legitimate websites — including news outlets and a hospital — were silently infected with backdoors. No download prompt. No “click here.” No mistake by the victim at all. One page visit was enough — if the visitor’s computer was running an outdated version of one specific program. Researchers found evidence of related intrusions at 72 organizations.

And here’s the twist that earns this story a spot on your reading list: the vulnerable program was security software — a digital-signature tool that South Korean banking and government websites effectively require users to install. The very thing installed to make people safer became the unlocked door. The campaign is attributed by the advisory to a state-sponsored group; the geopolitics aren’t our beat. The mechanics are — because they carry two lessons every business and household needs.

The attack, at a glance

The setupAttackers quietly compromised 15 legitimate, trusted websites — news sites and a hospital among them — and planted exploit code on their pages
The triggerVisiting a booby-trapped page with an outdated version of a widely installed security program (versions 1.1.4.4 through 1.1.4.6 of a tool called AnySign4PC)
The resultA backdoor installed silently — no prompt, no download dialog, no user action — giving attackers ongoing remote access
The scaleEvidence of related intrusions at 72 organizations, per researchers; a joint government-industry advisory issued
The fixUpdating the software (version 1.1.5.0) closes the hole; authorities also recommend simply deleting the program if it isn’t actively needed

Lesson one: security software is still software

There’s a natural instinct to treat security tools as a different category of thing — the guards, not the doors. They’re not. Every program on a machine, including the ones protecting it, is code that can carry flaws, and security tools often run with deeper access to the system than anything else, which makes a flaw in them worth more to an attacker, not less. We saw the same shape in this month’s critical Zoom flaw: trusted, ubiquitous software, quietly holding a serious hole until its update arrived. The lesson isn’t “trust nothing.” It’s that everything installed needs updating — especially the things you trust most.

The part that should change how you think: there was no ask to refuse. Our usual advice — spot the trick, refuse the download, distrust the urgency — assumes the attack needs a human mistake. This one needed none. When the attack is “visit a real website while running old software,” vigilance can’t save you. Only updates can. That is why patching isn’t an IT chore; it is the entire defense for a whole class of attack.

Lesson two: if you don’t need it, remove it

Buried in the official guidance is a recommendation worth framing: if the vulnerable program isn’t actively needed, delete it. Every installed program is standing attack surface — and most computers, in most businesses, are barnacled with software nobody has used in years. The plugin from an old vendor. The tool for a project that ended in 2022. The trial that never got removed. The required-by-some-website helper installed once and forgotten. None of it feels like risk because none of it gets thought about at all — which is exactly the condition this campaign feasted on. Software you don’t run anymore still runs its risks.

What this means on your side of the ocean

This campaign targeted a specifically Korean program, so no — your machines almost certainly don’t have this exact hole. But the pattern travels perfectly, and we’ve already seen it here: trusted websites get hijacked in the U.S. too, and outdated software of every kind is what turns a hijacked page from an annoyance into an infection. Put the two lessons together and the takeaway for any business is plain:

  • Everything updates, or someone owns knowing why not — the browser, the operating system, the PDF reader, the “helper” tools, and yes, the security software itself, on every machine you have.
  • Everything installed earns its place, or it goes. A periodic sweep of “what is on these machines and why” is one of the cheapest defenses that exists.
  • Nobody owns this job by default. In businesses without an IT department, “keep dozens of programs current on every machine, forever” belongs to no one — which means it doesn’t happen.

The honest questions: Could anyone in your business say what software is installed across your machines right now? * When something publishes a security fix, how long until every one of your computers actually has it? * And what’s still installed from 2021 that nobody has opened since?

Those questions are the job description of our managed IT service: an inventory of every machine, software kept current everywhere, the barnacles scraped off, and the patch race won on your behalf, month after month, without you thinking about it. Seventy-two organizations just learned what one outdated, forgotten program can cost. The businesses that never learn that lesson are the ones where somebody owns the updates. Let that somebody be us.

Sources: joint South Korean government-industry advisory (KISA, NIS, NPA, FSI); AhnLab; ENKI Whitehat; S2W; The Hacker News, July 2026. Attribution is as stated in the advisory.

From the same category