Summary
Key Points:
- North Korean threat actors are deploying a new Linux espionage toolkit targeting automotive and media organizations in South Korea, featuring a backdoor called 'ted' integrated into HAProxy.
- The toolkit enables long-term surveillance through remote command execution, credential harvesting, and script injection, impacting systems running HAProxy version 2.8.12 and related services.
- Recommended actions include monitoring for unusual HAProxy activity, implementing strict access controls, and conducting regular security audits to detect potential exploitation of Groupware login portal vulnerabilities.
Technical Details: The toolkit utilizes a custom HAProxy plugin for traffic interception and command execution, alongside a curl-based RAT for credential harvesting. Initial access was gained through exploiting a Groupware login portal vulnerability.
MITRE ATT&CK Techniques:
- T1078 - Valid Accounts (Defense Evasion)
- T1190 - Exploit Public-Facing Application (Initial Access)
- T1040 - Network Sniffing (Credential Access)
- T1053.005 - Scheduled Task/Job: Scheduled Task (Persistence)
- T1071.001 - Application Layer Protocol: Web Protocols (Command and Control)
IOCs Mentioned: None mentioned
Join the discussion — sign up to comment, upvote, and save articles.