North Korean hackers have developed and deployed an advanced Linux toolkit aimed at conducting espionage against South Korean automotive and media sectors, cybersecurity firm Rapid7 reports. This toolkit is specifically designed for prolonged surveillance, providing capabilities for remote command execution, credential theft, and web traffic manipulation.
Components of the Espionage Toolkit
The espionage framework includes a HAProxy instance, referred to as the ‘ted backdoor’, along with modified versions of tools like ‘agetty’, ‘atd’, ‘crond’, ‘polkitd’, and ‘sshd’. These components enable the attackers to seamlessly integrate into the target’s infrastructure, facilitating long-term undetected surveillance.
Rapid7 explains that the backdoor is embedded into HAProxy version 2.8.12, running within the victim’s environment. It leverages HAProxy’s native functionalities to intercept and obscure traffic while maintaining standard load balancing operations.
Method of Initial Access
The attackers gained initial server access by exploiting a vulnerability in a Groupware login portal. Once inside, an SSH keylogger served dual purposes: harvesting credentials and acting as a staging server, allowing for lateral movement within internal systems.
The toolkit’s stager assesses the presence of ‘crond’ or ‘HAProxy’ before deploying CurlRAT, retrieving it from its data section or an edge web server. The ‘ted backdoor’ is then deployed onto the HAProxy load balancer, setting up command and control (C&C) communications for data exfiltration and malicious content delivery.
Espionage Techniques and Attribution
The toolkit’s CurlRAT component polls the C&C server every 12 hours for instructions, enabling command decryption and execution. The ‘ted backdoor’, integrated within HAProxy’s HTTP parser, facilitates HTTP traffic interception and injection, achieving persistence and ongoing espionage.
Evidence suggests the use of watering-hole techniques, akin to those previously employed by APT37 and Lazarus Group. The timeframe of these operations overlaps with historical campaigns such as Operation SyncHole, reinforcing suspicions of North Korean involvement in this espionage activity.
In conclusion, the deployment of this sophisticated toolkit highlights the evolving strategies of state-aligned cyber actors in conducting prolonged espionage. With the ongoing threat of such cyber operations, organizations are urged to bolster their cybersecurity defenses and remain vigilant against potential intrusions.
