North Korean Hackers Deploy New Linux Espionage Toolkit
The stealthy toolkit embeds a backdoor in HAProxy and targets automotive and media organizations in South Korea for long-term surveillance. The post North Korean Hackers Deploy New Linux Espionage Toolkit appeared first on SecurityWeek.
North Korea-aligned threat actors have been using a new Linux toolkit in attacks targeting automotive and media organizations in South Korea, Rapid7 reports.
Designed for long-term surveillance, the framework consists of a HAProxy instance called ‘ted backdoor’ and trojanized versions of tools such as ‘agetty’, ‘atd’, ‘crond’, ‘polkitd’, and ‘sshd’.
The toolkit supports remote command execution, credential harvesting, and script injection into web traffic, enabling attackers to spy on victims for long periods of time without detection.
Source: https://www.securityweek.com/north-korean-hackers-deploy-new-linux-espionage-toolkit/
Related breach coverage
- North Korea-linked Hackers Hide a Backdoor Inside HAProxy2026-09-08
North Korea-linked hackers hid a backdoor inside HAProxy, masking C2 traffic and stealing data while keeping the load balancer working normally. North Korean-linked hackers found a genuinely clever hiding spot for their malware: inside the actual source code of HAProxy, the load balancing software running at the edge of two South Korean companies’ networks. Rapid7’s […]
- Adobe Commerce Zero-Day Exploited to Backdoor Online Stores2026-09-07
The StyleSmuggler zero-day allows attackers to execute code and deploy a stealthy backdoor on Adobe Commerce and Magento stores. The post Adobe Commerce Zero-Day Exploited to Backdoor Online Stores appeared first on SecurityWeek.
- Rust Supply Chain Attack Linked to North Korean Hackers2026-08-21
Hackers pushed a poisoned arrayref version that added a dependency to fetch a malicious payload from a remote server. The post Rust Supply Chain Attack Linked to North Korean Hackers appeared first on SecurityWeek.
- PaperCut Flaws Exploited in AI-Powered Attacks2026-09-11
A Russian threat actor used AI to build, test, and deploy exploits against hundreds of organizations worldwide. The post PaperCut Flaws Exploited in AI-Powered Attacks appeared first on SecurityWeek.