Cyber Op Targets South Korean Media & Automotive Sectors
Recorded: Sept. 16, 2026, 3:10 a.m.
| Original | Summarized |
Cyber Op Targets South Korean Media & Automotive Sectors Informa TechTarget|Cybersecurity DiveInformationWeekChannel DiveTechTarget: CybersecurityExplore our brandsAn Informa TechTarget PublicationDark Reading Resource LibraryBlack Hat NewsOmdia CybersecurityAdvertiseNewsletter Sign-UpNewsletter Sign-UpCybersecurity TopicsRelated TopicsApplication SecurityCybersecurity CareersCloud SecurityCyber RiskCyberattacks & Data BreachesCybersecurity AnalyticsCybersecurity OperationsData PrivacyEndpoint SecurityICS/OT SecurityIdentity & Access Mgmt SecurityInsider ThreatsIoTMobile SecurityPerimeterPhysical SecurityRemote WorkforceThreat IntelligenceVulnerabilities & ThreatsRecent in Cybersecurity TopicsApplication SecurityMicrosoft Issues Emergency Fixes After Massive Patch TuesdayMicrosoft Issues Emergency Fixes After Massive Patch TuesdaybyRob WrightSep 15, 20263 Min ReadVulnerabilities & ThreatsBlack Hat USA 2026 | The 'Breaking' News: The OpenAI–Hugging Face IncidentBlack Hat USA 2026 | The 'Breaking' News: The OpenAI–Hugging Face IncidentSep 15, 2026World Related TopicsDR GlobalAsia PacificEuropeLatin AmericaMiddle East & AfricaSee AllThe EdgeDR TechnologyEventsRelated TopicsUpcoming EventsPodcastsWebinarsSEE ALLResourcesRelated TopicsResource LibraryWhite PapersReportsWebinarsNewslettersPodcastsHeard It From a CISOReporters' NotebookDark Reading's 20thVideosDark Reading PollsPartner PerspectivesMeet the EditorsAdvertise With Us About UsDark Reading Resource LibraryCyberattacks & Data BreachesApplication SecurityThreat IntelligencePerimeterNewsBreaking cybersecurity news, news analysis, commentary, and other content from around the world, with an initial focus on the Middle East & Africa, the Asia Pacific, Europe, and Latin America.Cyber Op Targets South Korean Media & Automotive SectorsA likely North Korean advanced persistent threat (APT) group used a previously undocumented Linux espionage toolkit to compromise load balancers, gain access to communications, and further exploit networks.Robert Lemos,Contributing WriterSeptember 16, 20264 Min ReadSource: QQMinh88 via ShutterstockStealthy attacks on South Korean automotive and media firms have given an espionage group access to victims' networks — operating, in some cases, since early 2025.In an analysis this week, Rapid7 attributed the attack to North Korean advanced persistent threat (APT) groups — although only with medium confidence — because of the targets of the attacks, the use of simple obfuscation, and a list of command-and-control (C2) servers that matches those used by APT37, also known as InkySquid, ScarCruft, and Ricochet Chollima. The focus on media companies could give the attackers access to source networks, unpublished reporting, and journalist communications, while automotive companies could be a gateway to manufacturing intellectual property and technology, according to Rapid7's researchers, who asked not to be cited by name in an interview with Dark Reading."Together, the two sectors suggest at least two concurrent objectives: information control and counterintelligence from the media side, and manufacturing technology intelligence from the automotive side," they note.Related:Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear AgencyIn the past, North Korean hackers have targeted financial firms, accounting for the lion's share of cryptocurrency stolen in 2026. Other attacks have used deepfake military IDs to fool users and used traditional spearphishing against South Korean embassy personnel.In this case, the group behind the attacks compromised popular open source load balancer software, known as HAProxy, to install a hard-to-detect Linux toolkit (dubbed "TED") and gain complete access to incoming and outgoing traffic, cybersecurity firm Rapid7 stated in its analysis of the group this week. Once resident in the victims' network appliances, the cyber-threat group — thought to be North Korean — conducted long-term espionage operations, including harvesting credentials, redirecting select users, conducting drive-by-download attacks, and modifying log files to hide their tracks.The compromise of a load balancer, followed by installing custom compiled code into the appliance's software, is an iterative improvement for APT groups from North Korea, according to Rapid7's research group.The attack "fits a consistent the Democratic People's Republic of Korea (DPRK) pattern of initial access through trusted software or exposed infrastructure, long dwell times, credential harvesting, and watering-hole techniques targeting specific professional communities," they say. "TED represents a further step by embedding into production infrastructure rather than running alongside it."Related:Russian Hackers Phish EU Officials Over Messaging AppsLiving Off the Load BalancerHAProxy is an open-source application load balancer and reverse proxy, which also forms the core of the enterprise offering HAProxy One. By compromising the load balancer, the attackers gain access to the appliance's own filter API, and so can gain direct access to already decrypted plaintext communication, rather than having to create a host-in-the-middle attack.While the specific initial access point is not known, two victims — whose identities Rapid7 did not divulge — ran edge Web servers with groupware and email login portals accessible, according to the company's analysis. Since the North Korean APT group Kimsuky is known to have compromised victims using remote exploits against email servers, those are likely initial-access points, Rapid7's analysis stated.Once a groupware server is compromised, the attackers used it as a launching point for the rest of their attacks while also harvesting credentials.After compromising an edge Web server, attackers implant a load balancer with a backdoor, TED, to gain access to communications. Source: Rapid7"From the attacker’s standpoint, the load balancer is an ideal location because SSL terminates there, it sits in front of all applications, and load balancers are often excluded from endpoint detection coverage because they are treated as network appliances rather than servers," Rapid7's research team says.Related:Dark Caracal Adds New Malware to Cyber Espionage ArsenalTechnically, the most impressive bit of the attack is a routine that scrubs the counters in the log files to hide the attackers' activity, showing that "someone spent serious time reading HAProxy source code and testing against a live instance," the research team says.The approach is only the latest example in a trend away from malware, with attackers instead burying malicious functionality inside legitimate software, the Rapid7 researchers say."Recent DPRK campaigns have progressed from using OS-native tools to avoid dropping binaries, to trojanizing legitimate software installers, to embedding directly into the runtime of production infrastructure components," they say. "TED represents that progression applied to a load balancer."Appliances Can be Cyber-Zombies TooCISOs in South Korea and the Asia-Pacific region should closely analyze their load balancers and other network appliances, Rapid7's researchers warn. A variety of integrity checks against code libraries and compiled binaries should be combined with audits of process memory and a comparison between on-device and out-of-band logs.Finding compromised devices is not an easy task."The implant generates no anomalous processes, no unexpected outbound connections and no log entries," the researchers say. "Its C2 response path writes directly to the raw TCP socket and bypasses HAProxy’s logging subsystem, while the counter-scrubbing prevents monitoring dashboards from showing anomalous activity."Regional CISOs should closely consider similar weak points in their own architectures and consider that network appliance could be compromised, the researchers say."Any load balancer or reverse proxy that handles SSL termination and supports runtime-loaded modules represents the same attack surface regardless of vendor," they say. "Organizations should apply the same endpoint detection discipline, including library integrity, memory baselining and independent network correlation, to infrastructure components that they already apply to application servers."Read more about:DR Global Asia PacificAbout the AuthorRobert LemosContributing WriterRob is an award-winning, veteran technology journalist of more than 30 years, reporting on global cybersecurity issues, the latest offensive and defensive technologies, malware incidents, cyber conflict, and AI's impact on software and cybersecurity.A former research engineer, Rob has written for more than two dozen publications, including CNET News.com, Dark Reading, MIT's Technology Review, Popular Science, and Wired News. He has received five awards for journalism, including Best Deadline Journalism (Online) in 2003 for his coverage of the Blaster worm. Rob also analyzes data on various trends using Python and R for both his reporting and his clients. Recent reports include analyses of the shortage in cybersecurity workers, annual vulnerability trends, and annual threat reports.Rob holds degrees from Cornell University in Electrical Engineering and Computer Science (double major).See more from Robert LemosWant more Dark Reading stories in your Google search results?Add Us NowMore InsightsIndustry ReportsThe State of Cloud Security: The Latest ChallengesHow Organizations Are Managing Incident ResponseHow Enterprises Are Developing Secure ApplicationsInside RSAC 2026: security leaders reveal the risks redefining your defense strategyEssential News & Insights from Black Hat USA 2025Access More ResearchWebinarsCybersecurity Outlook 2027Benchmark Scores Are a False FlagThreat Exposure Analytics: Measuring and Communicating Security RiskBuilding an Effective Red Team: Beyond Penetration TestingHow to Leverage Threat Intelligence Without Drowning: The Zero Noise ApproachMore WebinarsFeaturedCheck out the Black Hat USA 2026 Conference Guide for coverage and intel from — and about — the show!Editor's ChoiceCyber RiskAnthropic CEO: Time to Shift From Improving to Controlling AIAnthropic CEO: Time to Shift From Improving to Controlling AIbyElizabeth MontalbanoSep 14, 20266 Min ReadCyber RiskWhy AI Is So Good at Scamming HumansWhy AI Is So Good at Scamming HumansSep 11, 2026Want more Dark Reading stories in your Google search results?How Organizations Are Managing Incident ResponseNearly every organization faced a critical security incident last year, but most weren't equipped to contain it. Get the full findings in this free report.Download NowNovember 12, 2026 | VIRTUALWhat Every Enterprise Should Know About Securing Cloud Assets In the Age of AISave Your SpotKeep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.SubscribeDiscover MoreBlack HatOmdiaWorking With UsAbout UsMeet the EditorsAdvertiseReprintsJoin UsNewsletter Sign-UpFollow UsCopyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466.Home|Cookie Policy|Privacy|Terms of UseYour Privacy Choices |
A likely North Korean advanced persistent threat (APT) group is believed to have exploited previously undocumented Linux espionage toolkits to compromise the networks of South Korean media and automotive sectors. This cyber operation suggests a dual objective: achieving information control and counterintelligence within the media sphere while simultaneously gathering manufacturing technology intelligence from the automotive sector. Rapid7 attributed these stealthy attacks to North Korean APT groups, based on the nature of the targets, the use of simple obfuscation techniques, and the matching of command-and-control (C2) servers to those utilized by APT37, InkySquid, ScarCruft, and Ricochet Chollima. The focus on media organizations provided potential access to source networks, unpublished reporting, and journalist communications, whereas targeting automotive firms offered a pathway to intellectual property and manufacturing technology. The technical execution involved compromising popular open-source load balancer software, specifically HAProxy, to install a hard-to-detect Linux toolkit referred to as "TED," which granted the attackers complete control over incoming and outgoing traffic. This compromise represents an iterative evolution in the tactics of these APT groups, moving beyond traditional malware to embed malicious functionality directly into production infrastructure components, such as the load balancer. The position of the load balancer was strategically advantageous for the attackers because it handles SSL termination and is frequently excluded from endpoint detection coverage as it is treated as a network appliance rather than a conventional server. This makes such devices ideal hiding spots for malicious implants. The attackers utilized a compromised groupware server, likely gained through prior remote exploits against email servers, as a launching point to harvest credentials before implanting the load balancer with the TED backdoor. The research indicates that the attackers spent significant time analyzing the HAProxy source code and testing against live instances to scrub log file counters and hide their activity. This demonstrates a progression in technique, where adversaries are embedding malicious functions within legitimate software rather than deploying distinct malware. This pattern aligns with broader trends seen in recent DPRK campaigns, which have progressed from using native operating system tools to trojanizing legitimate installers, culminating in embedding directly into runtime production infrastructure. The implication for cybersecurity defenses is that organizations in the Asia Pacific region, particularly CISOs in South Korea, must closely scrutinize their load balancers and other network appliances, recognizing that these devices represent a shared attack surface regardless of the vendor. Researchers advise that organizations should implement comprehensive integrity checks across code libraries and compiled binaries, combine these with audits of process memory and comparisons between on-device and out-of-band logs to detect compromises, as finding implants on compromised devices is inherently difficult. The analysis confirms that implants utilizing this method intentionally avoid generating anomalous processes, unexpected outbound connections, or log entries, bypassing standard monitoring dashboards. |