Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
North Korean Hackers Target South Korean Firms with Backdoor

North Korean Hackers Target South Korean Firms with Backdoor

Posted on September 7, 2026 By CWS

South Korean automotive and media sectors have recently been infiltrated by a sophisticated digital toolkit aimed at compromising Linux systems for sustained access. This stealthy malware is embedded within software managing web interactions, enabling the attackers to monitor users, extract sensitive data, and alter web content on affected servers.

Intrusion Tactics and Techniques

The infiltration strategy appears to be meticulously crafted for long-term access rather than immediate disruption. Entry points likely included groupware portals or email servers, with the attackers using these as gateways to penetrate deeper into targeted networks. This approach underscores the persistent threat posed by covert Linux server intrusions, where malicious access remains undetected over extended periods.

Security experts at Rapid7 have linked this activity to North Korean operatives with medium certainty. According to a report shared with Cyber Security News, the campaign may have begun as early as 2025, though specific vulnerabilities exploited remain unidentified.

Technical Details of the Ted Backdoor

The primary tool used in these attacks, known as the Ted Backdoor, is a modified version of HAProxy 2.8.12, a widely used web traffic management software. Unlike standalone malicious software, this backdoor integrates into legitimate applications, leveraging their capabilities to inspect and manipulate web requests undetected.

This integration allows the attackers to capture session cookies, execute commands, and manipulate web content for targeted users. The malware’s covert command channel mimics routine requests to evade detection. Researchers also discovered components like an SSH keylogger and altered system utilities.

The CurlRAT malware complements the Ted Backdoor by providing remote control functions. It communicates with the attackers’ infrastructure to receive commands, execute tasks, and manage payloads, all while monitoring the status of the HAProxy service.

Implications and Defensive Measures

Rapid7’s analysis suggests that this combination of credential theft, data collection, and web manipulation points to long-term espionage objectives. The focus on South Korean media and automotive industries aligns with regional intelligence operations commonly associated with North Korean actors.

To counter these threats, organizations are advised to scrutinize edge systems managing web traffic and mail services, ensuring they match known software versions and configurations. It is crucial to investigate anomalies in web requests and unexpected network connections from load balancers.

Regular updates and patches for groupware and mail servers can mitigate entry risks. As demonstrated by recent espionage activities targeting Linux systems in Asia, a single compromised server can serve as a persistent entry point for further incursions.

Implementing robust network monitoring and rotating compromised credentials are essential steps in fortifying defenses against these sophisticated threats.

Cyber Security News Tags:CurlRAT, cyber defense, cyber espionage, Cybersecurity, DPRK, Linux intrusion, North Korean hackers, Rapid7, South Korea, Ted backdoor

Post navigation

Previous Post: Nightmare Eclipse Reveals Zero-Day Flaws in Major Software
Next Post: Cloud Security Risks Vary Across Major Platforms

Related Posts

Operation Dragon Whistle: Cyber Threat Unveiled Operation Dragon Whistle: Cyber Threat Unveiled Cyber Security News
FBI Warns of Ploutus Malware Draining ATMs Nationwide FBI Warns of Ploutus Malware Draining ATMs Nationwide Cyber Security News
10 Best Secure Network As a Service for MSP Providers 10 Best Secure Network As a Service for MSP Providers Cyber Security News
OpenClaw Marketplace Faces AI Agent Security Threats OpenClaw Marketplace Faces AI Agent Security Threats Cyber Security News
Chrome 0-Day, VMware Flaws Patched, Fortiweb Hack, Teams Abuse, and More Chrome 0-Day, VMware Flaws Patched, Fortiweb Hack, Teams Abuse, and More Cyber Security News
WhatsApp Developers Under Attack From Weaponized npm Packages with Remote Kill Switch WhatsApp Developers Under Attack From Weaponized npm Packages with Remote Kill Switch Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Roundcube Webmail Addresses 12 Security Vulnerabilities
  • North Korea Utilizes New Linux Toolkit in Espionage
  • Cloud Security Risks Vary Across Major Platforms
  • North Korean Hackers Target South Korean Firms with Backdoor
  • Nightmare Eclipse Reveals Zero-Day Flaws in Major Software

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Roundcube Webmail Addresses 12 Security Vulnerabilities
  • North Korea Utilizes New Linux Toolkit in Espionage
  • Cloud Security Risks Vary Across Major Platforms
  • North Korean Hackers Target South Korean Firms with Backdoor
  • Nightmare Eclipse Reveals Zero-Day Flaws in Major Software

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark