Threat Intel
North Korean APT Breaches South Korean Media and Auto Firms via New Linux Toolkit on HAProxy Load Balancers
A suspected North Korean APT deployed a previously undocumented Linux espionage toolkit, dubbed "TED," to compromise HAProxy load balancers in South Korean media and automotive companies. The attackers leveraged the compromised appliances to harvest credentials, redirect traffic, and execute drive‑by downloads, fitting the DPRK pattern of long‑term espionage via trusted software. Rapid7 links the activity to APT37 with medium confidence, highlighting the dual focus on information control and manufacturing IP.
A recent analysis by Rapid7 uncovered a sophisticated operation targeting South Korean media and automotive firms. The attackers, likely an APT group linked to North Korea, used a new Linux-based espionage toolkit—named TED—to infiltrate HAProxy load balancers, a common open‑source solution in many enterprises.
Attack Overview
- Initial compromise of HAProxy load balancers via vulnerable or exposed infrastructure.
- Installation of the TED toolkit directly into the appliance’s firmware, granting full control over inbound and outbound traffic.
- Long‑term persistence with credential harvesting, traffic redirection, drive‑by downloads, and log tampering.
Toolkit & Tactics
- TED is a Linux‑only, stealthy espionage framework that embeds itself into production infrastructure.
- Command‑and‑control servers match those previously used by APT37 (InkySquid, ScarCruft, Ricochet Chollima).
- Use of simple obfuscation and watering‑hole techniques aimed at professional communities.
Implications for Target Sectors
- Media companies risk exposure of unpublished reporting, source networks, and journalist communications.
- Automotive firms face potential theft of manufacturing technology and intellectual property.
- Both sectors could serve as gateways for broader geopolitical espionage efforts.
Recommendations
- Audit all load balancer deployments for known vulnerabilities and unauthorized modifications.
- Implement strict access controls and continuous monitoring for traffic anomalies on HAProxy appliances.
- Apply the latest security patches and consider moving critical workloads to hardened, hardened platforms.
- Maintain a robust incident response plan that includes rapid containment of compromised infrastructure.
"The use of a new, undocumented Linux toolkit shows the APT group’s evolving strategy to embed itself within core network components rather than running alongside them," notes a Rapid7 analyst.