Tech News
← Home  ·  All topics

Apt37

1 GoKawiil brief on this topic

Rapid7 links suspected North Korean hackers to breach of South Korean media, auto firms

Rapid7 reports that a stealthy espionage campaign has compromised South Korean automotive and media companies since early 2025, with medium-confidence attribution to North Korean APT37 based on overlapping command-and-control infrastructure. The attackers exploited the open-source HAProxy load balancer to install a custom Linux toolkit called TED, granting them visibility into and control over victims' network traffic.