North Korea-aligned threat actors used a new Linux toolkit to target automotive and media organizations in South Korea, enabling long-term surveillance through a custom HAProxy backdoor, trojanized system tools, and a curl-based RAT. The campaign leveraged a groupware login portal flaw for initial access, credential theft, traffic interception, and stealthy command execution, with links suggesting possible overlap with APT37 and Lazarus. #APT37 #Lazarus #Rapid7 #HAProxy #CurlRAT #tedbackdoor
Keypoints
- North Korea-aligned actors targeted South Korean automotive and media organizations.
- The toolkit used a custom HAProxy plugin called ted backdoor for covert control.
- Trojanized tools and CurlRAT enabled credential theft and remote command execution.
- Initial access came through a Groupware login portal vulnerability on an edge server.
- The campaign used watering-hole tactics and spoofed trusted web traffic to evade detection.
Read More: https://www.securityweek.com/north-korean-hackers-deploy-new-linux-espionage-toolkit/