North Korean Hackers Deploy New Linux Toolkit to Manipulate South Korean Web Traffic
AI-generated from multiple sources. Verify before acting on this reporting.
SEOUL — North Korean state-sponsored cyber actors known as APT37, also referred to as Kimsuky, have deployed a previously undocumented Linux toolkit named 'ted' to compromise web infrastructure in South Korea. The malicious code was discovered embedded within trojanized versions of HAProxy load balancers at two South Korean organizations on Thursday, Sept. 4, 2026.
The intrusion allows the attackers to intercept live web traffic and serve altered pages to visitors without their knowledge. Security researchers identified the 'ted' toolkit as a distinct piece of malware designed specifically for this type of man-in-the-middle operation. By compromising the load balancers, which sit between users and backend servers, the group gained the ability to modify content in real-time before it reached end-users.
The affected organizations have not been publicly named, but the incident marks a significant evolution in the tactics used by North Korean cyber units targeting South Korean entities. While APT37 has historically focused on espionage and data theft, this operation demonstrates a capability to actively manipulate public-facing digital services. The 'ted' toolkit operates silently within the Linux environment of the compromised servers, evading standard detection mechanisms until the altered traffic patterns were analyzed.
Experts note that the use of trojanized open-source software like HAProxy represents a sophisticated approach to supply chain compromise. By injecting malicious code into legitimate software updates or binaries, attackers can bypass traditional perimeter defenses that focus on external threats. The specific method used to deliver the compromised load balancers to the two South Korean targets remains unclear.
The motive behind this specific campaign has not been determined. North Korean state-sponsored groups have previously targeted financial institutions, government agencies, and media outlets in the region, often aligning their activities with broader geopolitical tensions. However, no official statement has been issued by Seoul or Pyongyang regarding this incident, and it is unknown whether the altered web pages contained political messaging, financial fraud schemes, or other content.
Cybersecurity firms are currently scanning for additional instances of the 'ted' toolkit across South Korean networks to determine the full scope of the breach. The discovery raises concerns about the potential for similar attacks on critical infrastructure and private sector organizations that rely on widely used load balancing software.
As investigators work to isolate the infected systems and restore clean versions of the software, questions remain regarding how long the attackers maintained access before detection. It is also unclear whether any data was exfiltrated during the period of interception or if the operation was solely focused on content manipulation. The incident underscores the growing complexity of cyber threats facing South Korea's digital ecosystem.