← Back to news

North Korean Hackers Deploy New Linux Espionage Toolkit

SecurityWeek07/09/2026, 12:12
Read full article →

Summary

AI-Generated

Key Points:

  • North Korean threat actors are deploying a new Linux espionage toolkit targeting automotive and media organizations in South Korea, featuring a backdoor called 'ted' integrated into HAProxy.
  • The toolkit enables long-term surveillance through remote command execution, credential harvesting, and script injection, impacting systems running HAProxy version 2.8.12 and related services.
  • Recommended actions include monitoring for unusual HAProxy activity, implementing strict access controls, and conducting regular security audits to detect potential exploitation of Groupware login portal vulnerabilities.

Technical Details: The toolkit utilizes a custom HAProxy plugin for traffic interception and command execution, alongside a curl-based RAT for credential harvesting. Initial access was gained through exploiting a Groupware login portal vulnerability.

MITRE ATT&CK Techniques:

  • T1078 - Valid Accounts (Defense Evasion)
  • T1190 - Exploit Public-Facing Application (Initial Access)
  • T1040 - Network Sniffing (Credential Access)
  • T1053.005 - Scheduled Task/Job: Scheduled Task (Persistence)
  • T1071.001 - Application Layer Protocol: Web Protocols (Command and Control)

IOCs Mentioned: None mentioned

Join the discussion — sign up to comment, upvote, and save articles.

Discussion

or to comment
Loading...

Loading comments...

Join 5,000+ security professionals

Get access to curated threat intel, upvote articles, join discussions, and build your karma in the SOC community.