North Korean Hackers Deploy New Linux Espionage Toolkit Targeting Automotive and Media Organizations
North Korea-aligned threat actors have developed and deployed a new Linux espionage toolkit in cyberattacks primarily aimed at automotive and media organizations in South Korea, according to a report by Rapid7. This sophisticated framework is designed for long-term surveillance and includes a custom HAProxy instance named 'ted backdoor,' alongside trojanized versions of legitimate tools such as 'agetty,' 'atd,' 'crond,' 'polkitd,' and 'sshd.' The toolkit facilitates remote command execution, credential harvesting, and script injection into web traffic, allowing attackers to maintain covert access and spy on victims for extended periods. The 'ted backdoor' is deeply integrated into the target infrastructure, compiled directly into HAProxy version 2.8.12, and uses its native filter API to intercept traffic while appearing as normal load balancing operations. Initial access was gained through exploiting a vulnerability in a Groupware login portal on an edge server, followed by the use of an SSH keylogger for ...