THREAT OPS › Threat News › DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors
DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors
<h2><span style="font-size: undefined;">Overview</span></h2><p style="direction: ltr;"><span style="font-size: undefined;">A new Linux toolkit, identified by Rapid7 Labs, has been targeting organizations across South Korea’s automotive and media industries with minimal detection. The campaign made use of a HAProxy instance named “ted backdoor”, alongside trojanized versions of crond, agetty, atd,
Attributed threat actors
- Lazarus GroupG0032
- KimsukyG0094
- AndarielG0138
- APT37G0067
MITRE ATT&CK techniques
- Standard EncodingT1132.001
- Pluggable Authentication ModulesT1556.003
- JavaScriptT1059.007
- Create or Modify System ProcessT1543
- Steal Web Session CookieT1539
- Match Legitimate Resource Name or LocationT1036.005
- System ChecksT1497.001
- VulnerabilitiesT1588.006
- Automated CollectionT1119
- System Information DiscoveryT1082
- Application Layer ProtocolT1071
- Native APIT1106
- Exploit Public-Facing ApplicationT1190
- TimestompT1070.006
- Protocol TunnelingT1572
- Archive Collected DataT1560
- Browser Session HijackingT1185
- Dynamic Linker HijackingT1574.006
- Abuse Elevation Control MechanismT1548
- Dynamic ResolutionT1568
- Web ServiceT1102
- Execution GuardrailsT1480
- Process DiscoveryT1057
- Exfiltration Over C2 ChannelT1041
- Unix ShellT1059.004
- Hijack Execution FlowT1574
- Obfuscated Files or InformationT1027
- CredentialsT1589.001
- Web Session CookieT1550.004
- Data EncodingT1132
- Web ProtocolsT1071.001
- Modify Authentication ProcessT1556
- Exploit Public-Facing ApplicationAML.T0049
- Reverse ShellAML.T0072
- Process DiscoveryAML.T0089
Indicators of compromise
- 4bb923eb040aa13ca8fd409c31ee4729c60ddff32e350efe1c5a4a9168a065f5sha256
- 5db1b6d52faf60b4f32d6fd0c7c938e4d05d29a14c32ded4a9668357c08b6a91sha256
- 09739441ed4599bac2f8159028f772f71e4b25c8badfff95574e56d7384f3dbesha256
- fea1bc36632c71e5a839803469ef60ac47595d36b2c50934ac109ade6df06e61sha256
- feeea9d0bf6ae7396d28271baa51ae50df5169ce5d32a516865856f91abc50b3sha256
- 8f30b57928934ae67478d0e690c91d046e35a638da098d02922a4a88a0fdb66csha256
- 72e70936f0dbe459142a1d867617c35f8d0cce5d18c6a49e1090a2a5adc8e558sha256
- a8bfab4de81a1acb04aacdf757346946b0f5e30f0c9f402004016d0e425119c7sha256
- 83f7d565b0465546027052b597af46eae3a199e7a91fcc2ab936341147349130sha256
- 7007a78d50a993cb174c685eba96eb442c9507e38fd9d8e5dffc712f613ec110sha256
- 6cf1b5e92a9c0756f597a5ddefb38eba32961c52efac7ab2a0aa52c639a8fc53sha256
- ed72f4cd8d467b5c5d95ae6aeca4aaeea14d79565d379c1ca5871a714727be16sha256
- d53c760c23b4405eb04ad0f20ead375440344b3bdf1fb7854ed12e40d155eabesha256
- 2f02b09d61d432134e994ad671258f523bbf289ae6091fd4eae192c60bd51b6fsha256
- a1d8af3a6acb731f07f72040eccb3450c1c83d40e29f736c2a63d35388660be4sha256
- 12810854c8b2c391b23e2e18b013e873d0369b0637aa3cf993136c07188ba3b8sha256
- 009a1e2d7a582a24e50cf2ffc2a005482c8e38f22bf5ed416053855f8d054e1esha256
- 94630b96f628c96a6bff7904b40ffc9ad67c86f8a4ff6080c3b524831c93f402sha256
- c8c68e629bba773a10ac80012d10bf19md5
- ecd427ea8330a4ff73618483e00b9b41md5
- https://threatfox.abuse.ch/browse/tag/RicochetChollima/url
- https://www.enki.co.kr/en/media-center/blog/analysis-of-kimsuky-s-attack-on-a-south-korean-groupware-vendor-using-a-new-gomir-family-varianturl
- https://image.ahnlab.com/atip/content/file/20241126/(ENG%20ver)Operation%20Code%20on%20Toast(full).pdfurl
- https://ics-cert.kaspersky.com/publications/reports/2023/09/25/apt-and-financial-attacks-on-industrial-organizations-in-h1-2023/#korean-speaking-activityurl
- https://blog.xlab.qianxin.com/funnull-resurfaces-exposing-ringh23-arsenal-and-maccms-supply-chain-attacks/url
- images.contentstack.iodomain
- img.darklights.storedomain
- img.worksongo.storedomain
- img.socialteams.storedomain
- pstatic.netdomain
- img.smartnords.sitedomain