Stealthy attacks on South Korean automotive and media firms have given an espionage group access to victims' networks — operating, in some cases, since early 2025.
In an analysis this week, Rapid7 attributed the attack to North Korean advanced persistent threat (APT) groups — although only with medium confidence — because of the targets of the attacks, the use of simple obfuscation, and a list of command-and-control (C2) servers that matches those used by APT37, also known as InkySquid, ScarCruft, and Ricochet Chollima. The focus on media companies could give the attackers access to source networks, unpublished reporting, and journalist communications, while automotive companies could be a gateway to manufacturing intellectual property and technology, according to Rapid7's researchers, who asked not to be cited by name in an interview with Dark Reading.
"Together, the two sectors suggest at least two concurrent objectives: information control and counterintelligence from the media side, and manufacturing technology intelligence from the automotive side," they note.
Related:Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency
In the past, North Korean hackers have targeted financial firms, accounting for the lion's share of cryptocurrency stolen in 2026. Other attacks have used deepfake military IDs to fool users and used traditional spearphishing against South Korean embassy personnel.
In this case, the group behind the attacks compromised popular open source load balancer software, known as HAProxy, to install a hard-to-detect Linux toolkit (dubbed "TED") and gain complete access to incoming and outgoing traffic, cybersecurity firm Rapid7 stated in its analysis of the group this week. Once resident in the victims' network appliances, the cyber-threat group — thought to be North Korean — conducted long-term espionage operations, including harvesting credentials, redirecting select users, conducting drive-by-download attacks, and modifying log files to hide their tracks.
The compromise of a load balancer, followed by installing custom compiled code into the appliance's software, is an iterative improvement for APT groups from North Korea, according to Rapid7's research group.
The attack "fits a consistent the Democratic People's Republic of Korea (DPRK) pattern of initial access through trusted software or exposed infrastructure, long dwell times, credential harvesting, and watering-hole techniques targeting specific professional communities," they say. "TED represents a further step by embedding into production infrastructure rather than running alongside it."
Related:Russian Hackers Phish EU Officials Over Messaging Apps
Living Off the Load Balancer
... continue reading