Skip to content
Tech News
← Back to articles

Cyber Op Targets South Korean Media & Automotive Sectors

read original get YubiKey 5 NFC Security Key → more articles
Why This Matters

This campaign highlights how North Korea-linked APT groups are shifting tactics to compromise trusted infrastructure like open-source load balancers, gaining stealthy, long-term access to sensitive industries. For businesses in media and manufacturing, it underscores growing risks around supply-chain and infrastructure-level attacks that can persist undetected for months while enabling espionage or IP theft.

Key Takeaways
Worth a Look

YubiKey 5 NFC Security Key — With APT groups targeting corporate networks in media and automotive sectors, hardware-based multi-factor authentication like YubiKey is a practical defense against credential theft and phishing that often precedes these intrusions. It's a simple, durable device that IT teams can deploy widely to harden account security against nation-state actors.

See YubiKey 5 NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

Stealthy attacks on South Korean automotive and media firms have given an espionage group access to victims' networks — operating, in some cases, since early 2025.

In an analysis this week, Rapid7 attributed the attack to North Korean advanced persistent threat (APT) groups — although only with medium confidence — because of the targets of the attacks, the use of simple obfuscation, and a list of command-and-control (C2) servers that matches those used by APT37, also known as InkySquid, ScarCruft, and Ricochet Chollima. The focus on media companies could give the attackers access to source networks, unpublished reporting, and journalist communications, while automotive companies could be a gateway to manufacturing intellectual property and technology, according to Rapid7's researchers, who asked not to be cited by name in an interview with Dark Reading.

"Together, the two sectors suggest at least two concurrent objectives: information control and counterintelligence from the media side, and manufacturing technology intelligence from the automotive side," they note.

Related:Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency

In the past, North Korean hackers have targeted financial firms, accounting for the lion's share of cryptocurrency stolen in 2026. Other attacks have used deepfake military IDs to fool users and used traditional spearphishing against South Korean embassy personnel.

In this case, the group behind the attacks compromised popular open source load balancer software, known as HAProxy, to install a hard-to-detect Linux toolkit (dubbed "TED") and gain complete access to incoming and outgoing traffic, cybersecurity firm Rapid7 stated in its analysis of the group this week. Once resident in the victims' network appliances, the cyber-threat group — thought to be North Korean — conducted long-term espionage operations, including harvesting credentials, redirecting select users, conducting drive-by-download attacks, and modifying log files to hide their tracks.

The compromise of a load balancer, followed by installing custom compiled code into the appliance's software, is an iterative improvement for APT groups from North Korea, according to Rapid7's research group.

The attack "fits a consistent the Democratic People's Republic of Korea (DPRK) pattern of initial access through trusted software or exposed infrastructure, long dwell times, credential harvesting, and watering-hole techniques targeting specific professional communities," they say. "TED represents a further step by embedding into production infrastructure rather than running alongside it."

Related:Russian Hackers Phish EU Officials Over Messaging Apps

Living Off the Load Balancer

... continue reading