Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
North Korea Utilizes New Linux Toolkit in Espionage

North Korea Utilizes New Linux Toolkit in Espionage

Posted on September 7, 2026 By CWS

North Korean hackers have developed and deployed an advanced Linux toolkit aimed at conducting espionage against South Korean automotive and media sectors, cybersecurity firm Rapid7 reports. This toolkit is specifically designed for prolonged surveillance, providing capabilities for remote command execution, credential theft, and web traffic manipulation.

Components of the Espionage Toolkit

The espionage framework includes a HAProxy instance, referred to as the ‘ted backdoor’, along with modified versions of tools like ‘agetty’, ‘atd’, ‘crond’, ‘polkitd’, and ‘sshd’. These components enable the attackers to seamlessly integrate into the target’s infrastructure, facilitating long-term undetected surveillance.

Rapid7 explains that the backdoor is embedded into HAProxy version 2.8.12, running within the victim’s environment. It leverages HAProxy’s native functionalities to intercept and obscure traffic while maintaining standard load balancing operations.

Method of Initial Access

The attackers gained initial server access by exploiting a vulnerability in a Groupware login portal. Once inside, an SSH keylogger served dual purposes: harvesting credentials and acting as a staging server, allowing for lateral movement within internal systems.

The toolkit’s stager assesses the presence of ‘crond’ or ‘HAProxy’ before deploying CurlRAT, retrieving it from its data section or an edge web server. The ‘ted backdoor’ is then deployed onto the HAProxy load balancer, setting up command and control (C&C) communications for data exfiltration and malicious content delivery.

Espionage Techniques and Attribution

The toolkit’s CurlRAT component polls the C&C server every 12 hours for instructions, enabling command decryption and execution. The ‘ted backdoor’, integrated within HAProxy’s HTTP parser, facilitates HTTP traffic interception and injection, achieving persistence and ongoing espionage.

Evidence suggests the use of watering-hole techniques, akin to those previously employed by APT37 and Lazarus Group. The timeframe of these operations overlaps with historical campaigns such as Operation SyncHole, reinforcing suspicions of North Korean involvement in this espionage activity.

In conclusion, the deployment of this sophisticated toolkit highlights the evolving strategies of state-aligned cyber actors in conducting prolonged espionage. With the ongoing threat of such cyber operations, organizations are urged to bolster their cybersecurity defenses and remain vigilant against potential intrusions.

Security Week News Tags:APT37, cyber attacks, Cybersecurity, Espionage, HAProxy, Lazarus Group, Linux toolkit, North Korea, Rapid7, South Korea

Post navigation

Previous Post: Cloud Security Risks Vary Across Major Platforms
Next Post: Roundcube Webmail Addresses 12 Security Vulnerabilities

Related Posts

Effective AI Compliance: The Power of Checklists Effective AI Compliance: The Power of Checklists Security Week News
Ransomware Attack Forces Kettering Health to Cancel Procedures Ransomware Attack Forces Kettering Health to Cancel Procedures Security Week News
Microsoft Addresses 83 Security Vulnerabilities in March Update Microsoft Addresses 83 Security Vulnerabilities in March Update Security Week News
Follow Pragmatic Interventions to Keep Agentic AI in Check Follow Pragmatic Interventions to Keep Agentic AI in Check Security Week News
Cisco ISE, CitrixBleed 2 Vulnerabilities Exploited as Zero-Days: Amazon Cisco ISE, CitrixBleed 2 Vulnerabilities Exploited as Zero-Days: Amazon Security Week News
AIVEX: A New Model to Mitigate Supply Chain Risks AIVEX: A New Model to Mitigate Supply Chain Risks Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Malicious Minecraft Mod Distributes Myth Stealer RAT
  • OpenAI Agents Overrun German Wiki Site, Spark Concerns
  • ScreenConnect Exploited to Spread Malicious Scripts
  • Roundcube Webmail Addresses 12 Security Vulnerabilities
  • North Korea Utilizes New Linux Toolkit in Espionage

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Malicious Minecraft Mod Distributes Myth Stealer RAT
  • OpenAI Agents Overrun German Wiki Site, Spark Concerns
  • ScreenConnect Exploited to Spread Malicious Scripts
  • Roundcube Webmail Addresses 12 Security Vulnerabilities
  • North Korea Utilizes New Linux Toolkit in Espionage

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark