Executive Summary
A North Korean advanced persistent threat group, likely APT37, conducted sophisticated espionage operations against South Korean media and automotive companies throughout 2025-2026. The attackers compromised HAProxy load balancers to deploy a custom Linux toolkit called 'TED', gaining access to decrypted communications and conducting long-term surveillance operations. The group harvested credentials, modified log files to hide their tracks, and maintained persistent access to target networks for intelligence collection on media sources and manufacturing technology.
This incident represents a significant evolution in APT tactics, demonstrating how threat actors are embedding malicious code directly into production infrastructure rather than deploying traditional malware. The targeting of critical industrial sectors and the sophisticated load balancer compromise technique highlight the growing threat to network appliances and the need for enhanced infrastructure security.
Why This Matters Now
Network appliances are increasingly targeted as attackers realize they often lack endpoint detection coverage while handling critical decrypted traffic, making this attack vector a priority concern for modern cybersecurity strategies.
Attack Path Analysis
North Korean APT group (likely APT37/InkySquid) compromised South Korean media and automotive organizations through initial exploitation of exposed email/groupware servers, escalated privileges to install the TED Linux toolkit on HAProxy load balancers, moved laterally through internal networks while harvesting credentials, maintained persistent command and control through direct TCP socket communication bypassing logging systems, exfiltrated sensitive communications and intellectual property over extended dwell times, and achieved strategic intelligence gathering objectives while maintaining stealth through log manipulation and counter-scrubbing techniques.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers exploited vulnerable email servers and groupware portals accessible from the internet, likely using remote exploits similar to known Kimsuky TTPs targeting email infrastructure
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Web Shell
Process Injection
Valid Accounts
Adversary-in-the-Middle
Disable Windows Event Logging
Exfiltration Over C2 Channel
Web Protocols
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Network Penetration Testing
Control ID: 11.3.1
NYDFS 23 NYCRR 500 – Penetration Testing
Control ID: 500.05
DORA – Identification
Control ID: Article 8
CISA ZTMM 2.0 – Network/Environment Pillar
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO 27001:2022 – Management of Technical Vulnerabilities
Control ID: A.12.6.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Automotive
Advanced Persistent Threat targeting load balancers exposes manufacturing IP, technology secrets, and supply chain data through compromised HAProxy infrastructure requiring enhanced segmentation and encrypted traffic monitoring.
Broadcast Media
APT group's media sector infiltration enables source network access, unpublished content theft, and journalist communication surveillance while bypassing traditional endpoint detection through network appliance compromise.
Telecommunications
Load balancer compromise creates critical infrastructure vulnerability allowing SSL termination exploitation, traffic interception, and communication harvesting demanding zero trust segmentation and multicloud visibility controls.
Computer Software/Engineering
HAProxy exploitation demonstrates progression from OS-native tools to production infrastructure embedding, requiring enhanced integrity checks, memory baselining, and Kubernetes security for software development environments.
Sources
- Cyber Op Targets South Korean Media & Automotive Sectorshttps://www.darkreading.com/cyberattacks-data-breaches/cyber-south-korean-media-automotiveVerified
- APT37 (Reaper) - MITRE ATT&CKhttps://attack.mitre.org/groups/G0067/Verified
- North Korean Cyber Threats - CISA Advisoryhttps://www.cisa.gov/news-events/cybersecurity-advisories/aa20-239aVerified
- HAProxy Official Security Informationhttps://www.haproxy.org/security/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce the blast radius of this North Korean APT campaign by constraining lateral movement from compromised HAProxy load balancers and limiting east-west traffic propagation through segmented network boundaries.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Cloud-native security fabric would likely constrain attacker reachability by reducing exposed attack surfaces through application-aware network policies and workload-specific access controls applied to internet-facing email infrastructure.
Control: Zero Trust Segmentation
Mitigation: Zero trust segmentation would likely constrain privilege escalation scope by isolating compromised groupware servers from load balancer infrastructure through workload-specific network boundaries and restricted inter-service communication paths.
Control: East-West Traffic Security
Mitigation: East-west traffic enforcement would likely reduce lateral movement scope by constraining internal network propagation from the compromised load balancer through application-aware policies and restricted inter-workload communication channels across network segments.
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility controls would likely constrain command and control communication by reducing available outbound network paths and limiting direct TCP socket communication through centralized traffic inspection and policy enforcement across cloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: Egress security controls would likely constrain data exfiltration scope by limiting outbound data transfer paths from the compromised load balancer and reducing the volume of sensitive information that could be transmitted through controlled external communication channels.
Residual impact would likely be limited to initially compromised systems with reduced organizational exposure, as segmentation controls would constrain the scope of strategic intelligence gathering and limit access to sensitive media and automotive sector assets.
Impact at a Glance
Affected Business Functions
- Media Content Production and Distribution
- Automotive Manufacturing and R&D
- Customer Communications Systems
- Intellectual Property Management
Estimated downtime: 7 days
Estimated loss: $500,000
Compromised communications including journalist source networks, unpublished reporting, internal communications, and automotive manufacturing intellectual property and technology. Load balancer compromise enabled access to plaintext communications and credential harvesting across multiple organizations.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with least privilege policies to prevent lateral movement from compromised edge servers to critical load balancers and internal infrastructure
- • Deploy East-West Traffic Security controls to monitor and restrict workload-to-workload communications, detecting anomalous traffic patterns between network appliances and internal systems
- • Enable Multicloud Visibility & Control with centralized policy enforcement to detect suspicious automation and repeated malformed requests targeting groupware and email systems
- • Implement Egress Security & Policy Enforcement with FQDN filtering to prevent unauthorized data exfiltration and detect communications to known APT37 command and control infrastructure
- • Deploy Encrypted Traffic inspection capabilities with HPE to ensure all data in transit is protected and monitored, preventing plaintext access even when SSL termination is compromised



