North Korean Hackers Deploy New Linux Espionage Toolkit

North Korean Hackers Deploy New Linux Espionage Toolkit
North Korea-aligned threat actors used a new Linux toolkit to target automotive and media organizations in South Korea, enabling long-term surveillance through a custom HAProxy backdoor, trojanized system tools, and a curl-based RAT. The campaign leveraged a groupware login portal flaw for initial access, credential theft, traffic interception, and stealthy command execution, with links suggesting possible overlap with APT37 and Lazarus. #APT37 #Lazarus #Rapid7 #HAProxy #CurlRAT #tedbackdoor

Keypoints

  • North Korea-aligned actors targeted South Korean automotive and media organizations.
  • The toolkit used a custom HAProxy plugin called ted backdoor for covert control.
  • Trojanized tools and CurlRAT enabled credential theft and remote command execution.
  • Initial access came through a Groupware login portal vulnerability on an edge server.
  • The campaign used watering-hole tactics and spoofed trusted web traffic to evade detection.

Read More: https://www.securityweek.com/north-korean-hackers-deploy-new-linux-espionage-toolkit/