Cyber Op Targets South Korean Media & Automotive Sectors
Rapid7 linked North Korea (APT37) to attacks on South Korean media companies and automakers since early 2025. Attackers compromised HAProxy load balancers and deployed a Linux tool called TED for espionage; victims were not named.
- HAProxy breached: TED backdoor gives access to decrypted traffic
- Attacks on South Korean media and auto industry since early 2025
- Tool erases log counters and creates no suspicious processes
- Rapid7 linked attack to APT37 with 'medium' confidence
Read next
Security