Cyber Attackers Use Undocumented Toolkit to Infiltrate South Korean Media and Automotive Firms
A sophisticated cyber attack has compromised multiple South Korean media and automotive companies, highlighting the ongoing threat posed by North Korea’s advanced persistent threat (APT) groups. The attackers used a previously undocumented Linux espionage toolkit, dubbed “TED”, to gain access to sensitive communications and further exploit networks.
The targeted firms likely fell victim to the attackers’ initial compromise of load balancers using HAProxy software. This open-source application load balancer and reverse proxy allowed the attackers to gain direct access to already decrypted plaintext communication, essentially turning the load balancer into a backdoor for their malicious activities. Once inside, they could intercept sensitive communications, steal credentials, and modify log files to cover their tracks.
Rapid7’s research suggests that the North Korean APT group behind this attack, thought to be APT37 or another similar group, is targeting media companies to gain access to source networks, unpublished reporting, and journalist communications. This could allow them to exert control over information flow in the country. The automotive sector is also a potential target, providing access to manufacturing intellectual property and technology.
The attackers’ use of load balancers as an entry point is a notable development in their tactics. By embedding custom compiled code into the appliance’s software, they can maintain long-term access to the network without being detected. This approach fits with North Korea’s pattern of initial access through trusted software or exposed infrastructure, followed by credential harvesting and watering-hole techniques targeting specific professional communities.
The fact that this attack has been ongoing since early 2025 raises concerns about the attackers’ ability to remain undetected for extended periods. The use of a previously undocumented toolkit suggests that North Korea’s APT groups are continually developing new tools and tactics to evade detection and achieve their objectives.
For businesses in South Korea and beyond, this incident serves as a reminder of the importance of robust cybersecurity measures. Organizations should prioritize regular software updates, monitor network activity closely, and maintain strong access controls to prevent similar attacks from succeeding. In particular, HAProxy users should ensure they are running up-to-date versions of the software and implement additional security measures to protect against potential backdoors.
As the threat landscape continues to evolve, it is essential for organizations to stay informed about emerging threats and tactics. By understanding the methods used by attackers like North Korea’s APT groups, businesses can better prepare themselves to defend against these sophisticated attacks.
Source: Dark Reading — 2026-09-16