Close Menu
NCIJ Network NCIJ Network
    What's Hot

    The Guardian view on the far right’s real weapon: it is the politics of powerlessness | Editorial

    September 7, 2026

    Two of the Universe’s Great Mysteries May Have Their Own Dimension

    September 7, 2026

    Axis Robotics Releases AXIS: A Browser-Based Data Engine With 207 Robot Manipulation Tasks and 50,129 Trajectories

    September 7, 2026
    Facebook X (Twitter) Instagram
    Trending
    • The Guardian view on the far right’s real weapon: it is the politics of powerlessness | Editorial
    • Two of the Universe’s Great Mysteries May Have Their Own Dimension
    • Axis Robotics Releases AXIS: A Browser-Based Data Engine With 207 Robot Manipulation Tasks and 50,129 Trajectories
    • North Korean Hackers Deploy New Linux Espionage Toolkit
    • Ethereum Maps Priorities for Upcoming Hegotá Upgrade
    • Boost for Europe’s energy diversification and cross-border gas flows as Western Balkans plug into Vertical Corridor
    • ‘Polarised Brazil’: Lula remains a ‘strong candidate’ despite the challenges of incumbency – Spotlight
    • Farage still Reform’s best hope as rivals struggle to match appeal to party faithful | Reform UK
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, September 7
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    North Korean Hackers Deploy New Linux Espionage Toolkit

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 7, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    North Korea-aligned threat actors have been using a new Linux toolkit in attacks targeting automotive and media organizations in South Korea, Rapid7 reports.

    Designed for long-term surveillance, the framework consists of a HAProxy instance called ‘ted backdoor’ and trojanized versions of tools such as ‘agetty’, ‘atd’, ‘crond’, ‘polkitd’, and ‘sshd’.

    The toolkit supports remote command execution, credential harvesting, and script injection into web traffic, enabling attackers to spy on victims for long periods of time without detection.

    According to Rapid7, the framework is deeply integrated within the target infrastructure, with the ted backdoor being compiled as part of the HAProxy version 2.8.12 running on the victim’s environment.

    “It uses its native filter API, internal memory pools, event scheduler, and process management infrastructure to intercept traffic and hide from monitoring, while genuine load balancing traffic operates as expected,” the cybersecurity firm explains.

    Likely in use since late 2024, when the first involved HAProxy iteration was released, the toolkit also uses a curl-based RAT, an SSH keylogger, and a stager.

    Advertisement. Scroll to continue reading.

    Initial access to an edge server was obtained through the exploitation of a Groupware login portal vulnerability. The SSH keylogger, which also serves as a staging server, was used for credential harvesting, enabling lateral movement to internal systems.

    “The stager checks for the presence of either crond or HAProxy, and only then deploys CurlRAT, retrieving it either from its data section or the edge web server. In parallel, the ted backdoor is dropped onto the HAProxy load balancer,” Rapid7 explains.

    The backdoor establishes C&C communication for data exfiltration, script injection, and command execution, and the balancer starts redirecting or serving malicious content to selected clients browsing through it.

    CurlRAT, the curl-based RAT deployed in the attacks, polls the C&C every 12 hours for commands. Based on these, it can decrypt and execute commands stored in its configuration, decode and write a new config payload to disk, and deploy a full interactive PTY shell.

    The ted backdoor is a custom HAProxy plugin compiled within the HAProxy source code, directly hooked into the balancer’s built-in HTTP parser. It can intercept and inject HTTP traffic, execute C&C tasks, and achieve persistence, among others.

    As part of the observed attacks, the threat actor used domains registered under low-cost commodity top-level domains (TLDs) and blended the payload delivery traffic into normal web browsing, mimicking Naver’s pstatic.net static content domain.

    “Ted backdoor and curlRAT were designed to persist during long-term espionage operations with the ability to steal cookie sessions, credentials, redirect selected users, conduct drive-by download attacks, and hide evidence of the tampered page to a specific range of IPs to evade detection,” Rapid7 notes.

    Attack artifacts recovered by the cybersecurity firm, along with the infrastructure used, point to watering-hole techniques previously used by APT37 and Lazarus, and the campaign timeframe overlaps with that of Operation SyncHole, attributed to Lazarus last year, which suggests that a North Korean threat actor might be behind this campaign as well.

    Related: US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks

    Related: US, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers

    Related: EU Targets Russian Intelligence Officers Accused of Running Cyber Spying Campaign

    Related: China, India-Linked Hackers Both Targeted Same Pakistani Police Force

    Deploy Espionage hackers Korean Linux North toolkit
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits

    Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

    Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks

    BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

    Mathspace discloses data breach affecting over 1 million people

    Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    The Guardian view on the far right’s real weapon: it is the politics of powerlessness | Editorial

    September 7, 2026

    Two of the Universe’s Great Mysteries May Have Their Own Dimension

    September 7, 2026

    Axis Robotics Releases AXIS: A Browser-Based Data Engine With 207 Robot Manipulation Tasks and 50,129 Trajectories

    September 7, 2026

    North Korean Hackers Deploy New Linux Espionage Toolkit

    September 7, 2026
    Latest Posts

    Book Review: ‘Pure Men’ by Mohamed Mbougar Sarr

    August 1, 2026

    Bitcoin ETFs Post First Monthly Inflow Since April

    August 1, 2026

    Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

    August 1, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    The Guardian view on the far right’s real weapon: it is the politics of powerlessness | Editorial

    September 7, 2026

    Two of the Universe’s Great Mysteries May Have Their Own Dimension

    September 7, 2026

    Axis Robotics Releases AXIS: A Browser-Based Data Engine With 207 Robot Manipulation Tasks and 50,129 Trajectories

    September 7, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.