Visualização normal

Hoje — 10 de Setembro de 2026Stream principal
  • ✇Cybersecurity News
  • Ted Backdoor Hides in HAProxy to Spy on South Korea Do Son
    The ted backdoor is DPRK Linux malware hidden inside HAProxy. It pairs with curlRAT to spy on South Korean media and automotive firms, Rapid7 reports. Related Posts: Phishing Attackers Repurpose AI ASCII Smuggling to Evade Detection Kimsuky Uses AI Agent Opencode to Create Phishing Decoys Passkey Social Engineering Attacks Breach Enterprise Cloud Data The post Ted Backdoor Hides in HAProxy to Spy on South Korea appeared first on Daily CyberSecurity.
     
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 2, September 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 2, September 2026           The Gentlemen Ransomware Attack on a Canadian Airline LAPSUS$ Group Resumes Chapter II and Teases New Victim Disclosure AUDIT TEAM Data Extortion Attacks on Four Organizations in South Korea, Germany, and Argentina
     

Ransom & Dark Web Issues Week 2, September 2026

Por:ATCP
9 de Setembro de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 2, September 2026           The Gentlemen Ransomware Attack on a Canadian Airline LAPSUS$ Group Resumes Chapter II and Teases New Victim Disclosure AUDIT TEAM Data Extortion Attacks on Four Organizations in South Korea, Germany, and Argentina
Ontem — 9 de Setembro de 2026Stream principal
  • ✇Security Affairs
  • North Korea-linked Hackers Hide a Backdoor Inside HAProxy Pierluigi Paganini
    North Korea-linked hackers hid a backdoor inside HAProxy, masking C2 traffic and stealing data while keeping the load balancer working normally. North Korean-linked hackers found a genuinely clever hiding spot for their malware: inside the actual source code of HAProxy, the load balancing software running at the edge of two South Korean companies’ networks. Rapid7’s research documents a previously undocumented Linux toolkit hitting South Korea’s automotive and media sectors, and the depth of
     

North Korea-linked Hackers Hide a Backdoor Inside HAProxy

8 de Setembro de 2026, 06:11

North Korea-linked hackers hid a backdoor inside HAProxy, masking C2 traffic and stealing data while keeping the load balancer working normally.

North Korean-linked hackers found a genuinely clever hiding spot for their malware: inside the actual source code of HAProxy, the load balancing software running at the edge of two South Korean companies’ networks. Rapid7’s research documents a previously undocumented Linux toolkit hitting South Korea’s automotive and media sectors, and the depth of integration here goes well beyond a typical backdoor bolted onto a system.

“A new Linux toolkit, identified by Rapid7 Labs, has been targeting organizations across South Korea’s automotive and media industries with minimal detection. The campaign made use of a HAProxy instance named “ted backdoor”, alongside trojanized versions of crond, agetty, atd, sshd, and polkitd.” reads the report published by Rapid7. “This previously undocumented framework enabled threat actors to execute remote commands on compromised servers, inject malicious scripts into web traffic, perform credential harvesting, and engage in long-term surveillance.”

The implant, which Rapid7 calls the “ted backdoor” based on debug strings the attackers left behind, isn’t a separate process running alongside HAProxy. It’s compiled directly into HAProxy’s own source code as a custom plugin, using the software’s native filter API, internal memory management, and event scheduler to intercept HTTP traffic while completely legitimate load balancing keeps running normally on top of it.

“The standout feature of this toolkit is its depth of integration with the target environment. The ted backdoor is compiled as part of the victim’s existing HAProxy version 2.8.12.” continues the report. “It uses its native filter API, internal memory pools, event scheduler, and process management infrastructure to intercept traffic and hide from monitoring, while genuine load balancing traffic operates as expected.”

Rapid7 explains, which is really the whole thesis of why this backdoor is so hard to spot: it’s not an addition to the software, it’s woven into it.

The backdoor receives commands through a surprisingly simple trick. The attackers send a request for a fake image at /favorite_list_2x_m500_ico.jpg. This switches the HAProxy filter into command-and-control mode.

The malware then saves the command in a named pipe and removes traces of the request from HAProxy’s internal counters. It also clears the forwarding buffers, so the request never reaches the backend server. The command ends at the load balancer, leaving nothing in the application logs to show that it happened.

This ability to erase its own traces makes the backdoor very different from a normal web shell. The C2 requests never reach the backend server and are also removed from HAProxy’s statistics.

As a result, neither the application logs nor HAProxy’s connection logs show that the attack happened. A security team checking the logs could find nothing suspicious because the backdoor has already erased the evidence.

Beyond remote command execution, the backdoor can quietly inject malicious scripts or entirely swap out page content for specific victims matched by IP address, browser fingerprint, or even a hidden authentication credential smuggled inside the Accept-Language header, effectively turning a company’s own load balancer into a watering hole against its own visitors. It also hooks response bodies carefully enough to hide the size difference caused by injected content, stripping the header that would let a browser notice the byte-range mismatch. That’s a level of protocol-level care that suggests real HAProxy internals expertise, not a quick copy-paste job.

The main backdoor also comes with a separate toolkit that modifies common Linux system daemons such as crond, agetty, atd, and sshd. These programs continue to work normally but also carry malicious features.

One component acts as an SSH keylogger. It captures passwords that administrators enter in plain text and quietly records them. Another tool, called curlRAT, contacts a remote server every 12 hours by default, or every 30 seconds when the attacker enables its fast-poll mode.

curlRAT also checks whether the system runs inside a virtual machine. If it does not find the expected signs, it refuses to run. This behavior suggests the attackers designed the malware to avoid sandboxes and other analysis environments.

Attribution here sits at medium confidence, and Rapid7 is upfront about the limits of what the evidence actually shows. The targeting pattern, simple XOR-based encryption, a custom substitution cipher, and command-server infrastructure already linked to APT37 by other threat intelligence feeds all point toward North Korean state involvement, with some technical overlap also drawing comparisons to a concurrent Lazarus Group campaign against South Korean media sites.

“Further evidence is necessary to make a more definitive assessment. Moreover, the presence of ngx_* prefixed routines within the ted backdoor suggest code reused from an nginx backdoor. The ngx_* prefixed routines were observed during the latest Funnull campaign, where (similar to our case) a custom nginx filter was registered to hook HTTP traffic, and simple XOR encryption was applied to the configuration file.” Rapid7 states. “However, other than a similar naming convention, no significant code-level overlaps exist to support a stronger linkage.”

If your organization runs HAProxy, or really any edge component handling SSL termination and traffic routing, the practical lesson here is uncomfortable but simple: that software deserves the same scrutiny as your actual application servers, not less. The Hacker News confirmed in early September that the specific command domains used in this campaign have already gone dark, returning no DNS records at all, which is useful for reviewing historical logs but does nothing to stop whatever comes next from the same operators. Checking a load balancer’s own logs isn’t enough anymore when the backdoor’s entire design goal is making sure those logs never see it in the first place.

“ted backdoor and curlRAT were designed to persist during long-term espionage operations with the ability to steal cookie sessions, credentials, redirect selected users, conduct drive-by download attacks, and hide evidence of the tampered page to a specific range of IPs to evade detection.” concludes the report. “Defenders should treat any edge component managing user traffic, SSL, or runtime modules with the same strict security standards as their main application servers. Relying on the component’s own logs is not enough; securing these systems requires independent network correlation, memory behavioral analysis, and binary integrity checks.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, North Korea)

Antes de ontemStream principal
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 1, September 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 1, September 2026           ZaWoo Data Extortion Attacks Against Multiple Organizations Worldwide Black X Ransomware Attack on a South Korean Automotive Parts Manufacturer Internal Data of a South Korean Asset Management and Investment Firm Offered for Sale
     

Ransom & Dark Web Issues Week 1, September 2026

Por:ATCP
2 de Setembro de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 1, September 2026           ZaWoo Data Extortion Attacks Against Multiple Organizations Worldwide Black X Ransomware Attack on a South Korean Automotive Parts Manufacturer Internal Data of a South Korean Asset Management and Investment Firm Offered for Sale
  • ✇Security Affairs
  • North Korea-linked IT Workers Are Getting Hired Inside Western Companies Pierluigi Paganini
    Huntress found five DPRK-linked workers hired in 2026 using fake identities, remote-access setups and proxy tools to infiltrate legitimate companies. Companies keep accidentally hiring North Korea-linked individuals as remote workers, and Huntress just published the receipts. The security firm’s investigation documents five confirmed cases in 2026 alone where DPRK-aligned workers, tracked under the name FAMOUS CHOLLIMA, talked their way into legitimate jobs using fake or stolen identities, s
     

North Korea-linked IT Workers Are Getting Hired Inside Western Companies

1 de Setembro de 2026, 08:08

Huntress found five DPRK-linked workers hired in 2026 using fake identities, remote-access setups and proxy tools to infiltrate legitimate companies.

Companies keep accidentally hiring North Korea-linked individuals as remote workers, and Huntress just published the receipts. The security firm’s investigation documents five confirmed cases in 2026 alone where DPRK-aligned workers, tracked under the name FAMOUS CHOLLIMA, talked their way into legitimate jobs using fake or stolen identities, spanning IT roles, sales and marketing, and even healthcare positions.

The main challenge is that this isn’t a typical cyberattack. These workers get hired, complete the onboarding process and often perform the job they’re paid to do, while sending part of their earnings back to North Korea.

Huntress says the workers aren’t breaking into companies through technical vulnerabilities. Instead, they use fake identities and other tricks to get legitimate jobs, which makes them much harder to spot with traditional security tools.

“DPRK workers present a unique detection challenge for defenders: rather than compromising accounts or breaking in via gaps in the organisations’ environments, they’re tricking companies into remotely hiring them, and oftentimes actually doing the legitimate work they were hired to do.” reads Huntress’s report. “Furthermore, DPRK workers often use stolen identity documents, VPNs, and proxy services to mask their true identity and location, meaning other methods must be used to help verify if an employee is who they say they are.”

The first case, involving three suspected workers at an Australian healthcare partner, came together through document forensics rather than network telemetry. Two employees submitted identity documents, Chinese passports, resident ID cards, and electricity bills, that looked legitimate individually but shared an impossible number of coincidences: identical passport issue cities, dates of issue just one day apart, matching residential streets, and photo metadata showing the same iPhone model used eight minutes apart. Even the fake electricity bills shared the exact same typo, “hassle” rendered as “hassic,” a translation artifact from whatever template both documents were built from.

The second case reads like something out of a spy thriller, except the tradecraft is disturbingly mundane. A newly onboarded worker’s laptop connected to a GL.iNet travel router for hours despite apparently already having arrived at its destination, then landed on a residential WiFi network, then got hooked up to a PiKVM, a Raspberry Pi-based device that gives someone full remote control over a computer at the hardware level, before the OS even boots. Ten minutes after the PiKVM activated, the laptop switched to a permanent ethernet connection and never touched WiFi again, the telltale sign of a machine settling into what Huntress calls a laptop farm.

What gives this timeline away isn’t the PiKVM alone, it’s the almost comically ordinary activity that surrounds it. Within an hour of the device connecting, the worker was googling online audio tests and microphone test websites to make sure their setup actually worked, the exact kind of mundane troubleshooting anyone does with new hardware. A few days later they entered a personal Gmail address into a web form that happened to match a naming pattern Huntress had already tied to other DPRK operatives, and checked their own public IP address minutes before joining a Zoom call, presumably confirming their proxy setup was holding.

The third case, caught through proactive threat hunting rather than a partner tip, showed a slightly different playbook built around remote collaboration tools rather than hardware. This worker used Toffeeshare, an encrypted peer-to-peer file transfer service, to move identity documents that turned out to belong to a real person whose photo had been digitally swapped for the impostor’s face, likely to pass an I-9 employment verification check. They also posted recurring Zoom meeting links, complete with embedded passwords, on a public code-sharing site, and used VDO.Ninja, free streaming software, seemingly to broadcast their own screen for a remote operator watching elsewhere.

The identity theft angle here is worth sitting with for a moment. Huntress found that the stolen identity in this third case belonged to someone whose mugshot had previously circulated online following a real arrest, matching on full name, date of birth, and even the drivers license location, with only the face swapped out. That’s not a fabricated identity built from scratch; it’s a real, searchable person’s life quietly repurposed to get someone else hired at a company that had no way of knowing the documents didn’t belong to the face on the video call.

“The user accessed ip[.]me directly to determine their public-facing IP address just minutes before joining a Zoom meeting.” continues the report. “The employee also retrieved an image from a file-sharing site, potentially for use on an internal communications tool, which is highly suspicious and a red flag in itself”

Huntress recommends looking at several warning signs together rather than relying on one indicator. For example, monitor Windows logs for PiKVM and Guermok capture devices, especially when both appear on the same computer. Also watch for VPN or proxy services such as Astrill and IPRoyal combined with unusual working hours. Recently issued identity documents can also deserve extra checks.

None of these signs proves malicious activity on its own, since VPNs and proxies can have legitimate uses. But when several indicators appear together, for example, a new employee connects a KVM device, tests the microphone, works mainly around midnight UTC and provides an identity document issued at the same time as a coworker’s, the combination should trigger a proper background check before the person gets access to production systems.

“Since fraudulent workers are legitimately onboarded employees, identifying them post-hire involves manual effort and multiple points of evidence that, while individually are not indicative of malice, combined together present a much stronger picture of DPRK worker activity.” concludes the report. “Mitigating the risk of fraudulent workers begins at the interview stage and continues with performing rigorous background checks of new hires prior to onboarding. When in doubt, performing standard background checks, searching the individuals online, and verifying any employment history will help to weed out DPRK workers early in the interview process.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, North Korea-linked IT Workers)

  • ✇Cybersecurity News
  • Kimsuky Spear Phishing Abuses Remote Control Tools Do Son
    Recent Kimsuky spear phishing campaigns abuse remote control tools and AI extensions to target victims in Japan and South Korea. Read the full analysis. Related Posts: ValleyRAT Backdoor Spread via Signed Chinese Adware UAT-10147 Deploys SPECTRE Cross-Platform Implant Fire Ant Threat Actor Targets Trusted Infrastructure The post Kimsuky Spear Phishing Abuses Remote Control Tools appeared first on Daily CyberSecurity.
     
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 4, August 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 4, August2026           Saudi Arabian Digital Entertainment Streaming Service User Data Offered for Sale SAFEPAY Ransomware Attack on a South Korean Industrial Gas Manufacturer and Supplier NoName057(16) and BD Anonymous Claim DDoS Attacks Against Major Japanese Organizations and Companies [1] [2] [3] […]
     

Ransom & Dark Web Issues Week 4, August 2026

Por:ATCP
26 de Agosto de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 4, August2026           Saudi Arabian Digital Entertainment Streaming Service User Data Offered for Sale SAFEPAY Ransomware Attack on a South Korean Industrial Gas Manufacturer and Supplier NoName057(16) and BD Anonymous Claim DDoS Attacks Against Major Japanese Organizations and Companies [1] [2] [3] […]
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 3, August 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 3, August 2026         Customer and Operational Data of a South Korean Delivery Platform Offered for Sale Unauthorized Access Incident at a Japanese Cloud and Data Center Services Company ShinyHunters Threatens Data Disclosure Against a U.S. Live-Streaming Platform
     

Ransom & Dark Web Issues Week 3, August 2026

Por:ATCP
19 de Agosto de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 3, August 2026         Customer and Operational Data of a South Korean Delivery Platform Offered for Sale Unauthorized Access Incident at a Japanese Cloud and Data Center Services Company ShinyHunters Threatens Data Disclosure Against a U.S. Live-Streaming Platform
  • ✇Security Affairs
  • North Korean Lazarus Group Uses Windows Zero-Day in Operation Dream Job Pierluigi Paganini
    Lazarus targets defense professionals with fake Lockheed Martin jobs, exploiting a Windows zero-day to deploy backdoors and evade security controls. Check Point Research has uncovered a new wave of Operation Dream Job, the long-running North Korean campaign that lures defense and aerospace professionals with convincing fake job offers. This iteration is more dangerous than previous versions: it includes a previously unknown Windows vulnerability now patched as CVE-2026-68820, a newly documen
     

North Korean Lazarus Group Uses Windows Zero-Day in Operation Dream Job

13 de Agosto de 2026, 04:05

Lazarus targets defense professionals with fake Lockheed Martin jobs, exploiting a Windows zero-day to deploy backdoors and evade security controls.

Check Point Research has uncovered a new wave of Operation Dream Job, the long-running North Korean campaign that lures defense and aerospace professionals with convincing fake job offers. This iteration is more dangerous than previous versions: it includes a previously unknown Windows vulnerability now patched as CVE-2026-68820, a newly documented backdoor called Troy, and command infrastructure built almost entirely from legitimate servers the attackers didn’t build, they hijacked them. Targets confirmed in France, Germany, Brazil, and India.

“The attackers used a previously unknown vulnerability in Windows (CVE-2026-68820) to gain full control of infected computers and evade EDR visibility. Check Point reported the issue to Microsoft, which released a fix before this research was published” reads the report published by Check Point Research. “Rather than running their own servers, the attackers are hijacking legitimate but compromised websites and webmail servers to relay commands, making the malicious traffic harder to distinguish from normal activity”

The vulnerability, CVE-2026-68820, is the same actively exploited zero-day that Microsoft patched on August 11 as part of Patch Tuesday, a privilege escalation flaw in AFD.sys, the kernel driver underlying Windows Sockets. Check Point reported the issue to Microsoft on July 28, Microsoft confirmed it three days later, and the fix shipped two weeks after that. The zero-day in this campaign and the zero-day under active exploitation are the same bug.

The attack runs through two parallel infection chains. In the first, victims download an encrypted archive containing a legitimate signed PDF viewer and a malicious DLL. The DLL displays a convincing Lockheed Martin job description while silently loading MISTPEN, a lightweight downloader that communicates through Microsoft Graph API and OneDrive. MISTPEN then runs reconnaissance modules, triggers the AFD.sys exploit to achieve SYSTEM privileges, and deploys ForestTiger, a well-documented Lazarus backdoor, along with an updated version of the group’s kernel-mode rootkit, FudModule 3.1, which can now tamper with Windows Smart App Control to bypass software verification.

“The second chain is more recent and shares several characteristics with a campaign described by ESET against the UAV sector in 2025. Victims are instructed to download SecurityPDF, a trojanized PDF viewer, from one of several websites impersonating Enveil, a legitimate privacy technology company with no actual connection to the attack. Once installed, the modified viewer inspects any PDF opened through it for a hidden marker.” continues the report. “When the marker is present, the application decrypts and launches an embedded payload that loads the Troy backdoor directly into memory.”

Troy is a single DLL implant that supports 17 operator commands covering file operations, shell access, process termination, in-memory DLL injection, and configuration updates. Its name comes from a PDB path embedded in the binary that Check Point also observed in earlier Lazarus samples. Enveil has no connection to the campaign; its brand was simply borrowed because it sounds credible to defense sector professionals.

The C2 infrastructure is built from compromised Roundcube webmail installations and WordPress sites, many vulnerable to CVE-2025-49113, infected with a previously undocumented PHP webshell called RelayShell. RelayShell functions as a relay rather than a traditional backdoor, exchanging commands and responses through simple text files. In at least one confirmed case, an already-breached French organization was used to send phishing messages to new victims — the attackers borrowed the company’s reputation to get past filters. Check Point identified at least 17 unique server identifiers in this relay network, with operators connecting through commercial VPNs to further obscure their location.

The most urgent action is applying the August 2026 Patch Tuesday update, which contains the CVE-2026-68820 fix. For organizations running public-facing Roundcube or CMS installations, the secondary risk is becoming part of the relay infrastructure rather than the intended target: the servers used in this campaign were compromised through leaked credentials and a known unpatched vulnerability, not anything exotic. The full indicators of compromise are in Check Point’s report.

“Given the combination of a zero day vulnerability that now have a patch, a new modular backdoor, and web based infrastructure designed to resemble legitimate traffic, security teams in these sectors should prioritize the August Patch Tuesday update, review the indicators of compromise published in Check Point Research publication, and apply the same level of scrutiny to unsolicited recruiting outreach that they would apply to any unverified download request.” concludes the report.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Lazarus)

  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 2, August 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 2, August 2026.           DragonForce Ransomware Attack on a South Korean Online Education Company Qilin Ransomware Attack on a South Korean Motor and Robotics Manufacturer ShinyHunters Claims Data Leak from a U.S. Digital Healthcare Company
     

Ransom & Dark Web Issues Week 2, August 2026

Por:ATCP
12 de Agosto de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 2, August 2026.           DragonForce Ransomware Attack on a South Korean Online Education Company Qilin Ransomware Attack on a South Korean Motor and Robotics Manufacturer ShinyHunters Claims Data Leak from a U.S. Digital Healthcare Company
  • ✇ASEC BLOG
  • July 2026 Dark Web Breach Incident Trend Report ATCP
    Note The July 2026 Dark Web Breach Incident Trend Report was compiled based on data breach cases posted on deep web and dark web forums. Due to the nature of some posts, it is difficult to fully verify their accuracy; some posts related to South Korea included AI-generated false data or cases where it could […]
     
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 1, August 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 1, August 2026           South Korean Automotive Parts Manufacturer’s Internal Server Access and Database Offered for Sale Data of a Turkish HR Consulting Company Offered for Sale Gunra Ransomware Attack on a South Korean Heavy Equipment Parts and Advanced Materials Manufacturer
     

Ransom & Dark Web Issues Week 1, August 2026

Por:ATCP
5 de Agosto de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 1, August 2026           South Korean Automotive Parts Manufacturer’s Internal Server Access and Database Offered for Sale Data of a Turkish HR Consulting Company Offered for Sale Gunra Ransomware Attack on a South Korean Heavy Equipment Parts and Advanced Materials Manufacturer
  • ✇Security Affairs
  • South Korea Warns of State-Backed Watering Hole Attacks Pierluigi Paganini
    South Korea warned that nation-state actors are using phishing and compromised websites to silently infect citizens and businesses. South Korea agencies (The National Intelligence Service, the National Police Agency, the Korea Internet & Security Agency, and the Financial Security Institute) jointly published an advisory warning that a state-backed hacking group is actively targeting South Korean citizens and businesses. The warning names two attack techniques: phishing emails and wateri
     

South Korea Warns of State-Backed Watering Hole Attacks

31 de Julho de 2026, 18:25

South Korea warned that nation-state actors are using phishing and compromised websites to silently infect citizens and businesses.

South Korea agencies (The National Intelligence Service, the National Police Agency, the Korea Internet & Security Agency, and the Financial Security Institute) jointly published an advisory warning that a state-backed hacking group is actively targeting South Korean citizens and businesses. The warning names two attack techniques: phishing emails and watering hole attacks, and it doesn’t sugarcoat how little a victim has to do wrong.

The phishing side runs on two tricks. In one version, attackers disguise themselves as job applicants and send a resume email with a link instead of an attachment, pointing to a blog or GitHub page the attacker controls. In the other, they impersonate an actual recruiter, sometimes hijacking a real headhunter’s email account, and attach a password-protected ZIP file labeled as a job offer that infects the machine the moment it’s opened.

The watering hole method is the part that should worry ordinary readers more. Attackers compromise legitimate sites people already trust, news portals and hospital websites among them, along with smaller sites that simply have weak security, and use them as launch points. As the advisory puts it, the danger is that “visiting the site alone can be enough to trigger an infection.”

That’s possible because the malicious code doesn’t rely on tricking the user into clicking “install.” It pairs the compromised website with an old, unpatched vulnerability sitting in security software already installed on the visitor’s PC, the kind of software Korean banking and government sites require. No prompt appears, no warning shows up, the page looks completely normal, and the infection happens silently in the background.

This lines up closely with what AhnLab documented separately in its own technical report, Operation Double Barrel, which the advisory cites directly as a reference. AhnLab traced the same watering hole technique across 15 compromised Korean websites between 2025 and mid-2026, hitting media outlets, hospitals, and manufacturers, and found the attackers exploiting flaws in two specific pieces of Korean financial security software to inject backdoors into legitimate Microsoft processes. In one especially odd case, the malicious code only activated when visitors used Naver’s Whale browser, a level of targeting precision that suggests real reconnaissance rather than a scattergun approach.

Once infected, the advisory lists what’s actually at stake, and it’s not a short list. Saved browser passwords and manually typed credentials get siphoned off, documents and photos get pulled from the machine, and infected computers become a stepping stone to infect every other device on the same office or home network. For businesses specifically, the advisory adds that stolen source code and customer data become leverage: “pay up, or we publish and distribute the data.”

None of the fixes here are exotic. The advisory tells individuals to update every piece of security software, especially old electronic-signature and authentication tools that rarely get touched after installation, turn on two-factor authentication, stop saving passwords in the browser, and never open an attachment or link from an unfamiliar sender without verifying it through an official channel first. Organizations get a longer list: network segmentation for critical servers, mandatory multi-factor authentication instead of shared default passwords, regular phishing-awareness training, and immediate reporting to the relevant agency the moment something looks off.

It’s a strange kind of milestone when a national intelligence service has to remind an entire country that clicking a news headline isn’t automatically safe anymore. But that’s effectively where things stand: the browser tab you already trust might be doing more than loading a page.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, South Korea)

  • ✇Graham Cluley
  • North Korea’s elite hackers turned on their own government – and got caught Graham Cluley
    For years, North Korea's state-trained hackers have been one of the world's most prolific robbers of banks - stealing huge sums of money from foreign financial instituions, draining cryptocurrency exchanges of billions, and funnelling the proceeds into the country's weapons programme. But now, in a remarkable twist, some of the same elite hackers appear to have decided to rob their own government instead. And, it doesn't sound as if it has ended that well for them. Read more in my article
     

North Korea’s elite hackers turned on their own government – and got caught

30 de Julho de 2026, 06:17
For years, North Korea's state-trained hackers have been one of the world's most prolific robbers of banks - stealing huge sums of money from foreign financial instituions, draining cryptocurrency exchanges of billions, and funnelling the proceeds into the country's weapons programme. But now, in a remarkable twist, some of the same elite hackers appear to have decided to rob their own government instead. And, it doesn't sound as if it has ended that well for them. Read more in my article on the Hot for Security blog.
  • ✇Graham Cluley
  • Smashing Security podcast #478: This job interview could destroy your company Graham Cluley
    You've been headhunted for a great job in cryptocurrency. All you have to do is complete a short online assessment - with your webcam on, of course, so they can verify who you really are. Which is ironic, because the person recruiting you doesn't exist. And North Korean hackers using this trick have already made off with $643 million in crypto this year alone. Meanwhile, researchers at UC San Diego have discovered that 2.2 million cars across the United States can be unlocked or immobilised b
     

Smashing Security podcast #478: This job interview could destroy your company

29 de Julho de 2026, 20:09
You've been headhunted for a great job in cryptocurrency. All you have to do is complete a short online assessment - with your webcam on, of course, so they can verify who you really are. Which is ironic, because the person recruiting you doesn't exist. And North Korean hackers using this trick have already made off with $643 million in crypto this year alone. Meanwhile, researchers at UC San Diego have discovered that 2.2 million cars across the United States can be unlocked or immobilised by anyone with a bit of Bluetooth kit - thanks to one aftermarket car alarm that made a truly spectacular cryptographic blunder. The bug has been sitting there since 2017. Nobody noticed. All this and more in episode 478 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Paul Ducklin.
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 5, July 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 5, July 2026           Termite Ransomware Attack on a U.S. Nonprofit Healthcare Provider ShinyHunters Claims Data Leak Involving a Global Accounting and Consulting Firm The Gentlemen Ransomware Attack on a South Korean IT Software Distributor and Infrastructure Service Provider
     

Ransom & Dark Web Issues Week 5, July 2026

Por:ATCP
29 de Julho de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 5, July 2026           Termite Ransomware Attack on a U.S. Nonprofit Healthcare Provider ShinyHunters Claims Data Leak Involving a Global Accounting and Consulting Firm The Gentlemen Ransomware Attack on a South Korean IT Software Distributor and Infrastructure Service Provider
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 4, July 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 4, July 2026           Source Code Collection of a South Korean Autonomous Robot Manufacturer Shared on a Cybercrime Forum Qilin Ransomware Attack on a Spanish Public Wastewater Management Organization RansomHouse Ransomware Attack on a Japanese Frozen Food and Logistics Company
     

Ransom & Dark Web Issues Week 4, July 2026

Por:ATCP
22 de Julho de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 4, July 2026           Source Code Collection of a South Korean Autonomous Robot Manufacturer Shared on a Cybercrime Forum Qilin Ransomware Attack on a Spanish Public Wastewater Management Organization RansomHouse Ransomware Attack on a Japanese Frozen Food and Logistics Company
  • ✇Firewall Daily – The Cyber Express
  • Hackers Lurked for 10 Months Inside South Korea Diplomatic System Ashish Khaitan
    The National Diplomatic Academy data breach has raised significant cybersecurity concerns in South Korea after the Ministry of Foreign Affairs confirmed that hackers maintained access to the academy's online education system for nearly 10 months. The cyberattack resulted in the exposure of personal information belonging to current and former ministry employees, including diplomats serving overseas.  According to the Ministry of Foreign Affairs, the attackers exploited a vulnerability in the N
     

Hackers Lurked for 10 Months Inside South Korea Diplomatic System

National Diplomatic Academy data breach

The National Diplomatic Academy data breach has raised significant cybersecurity concerns in South Korea after the Ministry of Foreign Affairs confirmed that hackers maintained access to the academy's online education system for nearly 10 months. The cyberattack resulted in the exposure of personal information belonging to current and former ministry employees, including diplomats serving overseas.  According to the Ministry of Foreign Affairs, the attackers exploited a vulnerability in the National Diplomatic Academy's online education platform in April 2025. The compromise remained active until February 2026, allowing unauthorized access to data linked to thousands of individuals before the incident was eventually discovered and contained. 

National Diplomatic Academy Data Breach Remained Active for Nearly 10 Months 

The National Diplomatic Academy data breach began in April 2025 after an unidentified threat actor exploited a security flaw in the academy's online education system. The platform, which was introduced in 2022 to support remote learning during the COVID-19 pandemic, has since been used for government employee training and video conferencing.  According to the Ministry of Foreign Affairs, personal information was exposed between April 2025 and February 2026.  In an official announcement, the ministry stated:  There was an unidentified attack exploiting a security vulnerability targeting the Korea National Diplomatic Academy's online education system, and it has been confirmed that personal information of former and current employees of the Ministry of Foreign Affairs headquarters and overseas missions, as well as other personnel, was leaked from April 2025 to February 2026."  The ministry said the attack affected current and former employees at its headquarters, overseas missions, and other personnel connected to the online education system. 

Thousands Impacted in South Korea Foreign Ministry Data Breach 

The National Diplomatic Academy data breach is estimated to have impacted at least 6,000 individuals, including approximately 350 government attachés currently stationed abroad. However, reports from Korean media suggest the number of affected individuals could be as high as 10,000, while other reports indicate lower figures.  In addition to personal information, local media reported that official job titles and departmental affiliations may also have been exposed during the incident.  The Ministry of Foreign Affairs has not confirmed the higher estimates but acknowledged that the breach affected a substantial number of current and former personnel associated with the diplomatic service. 

What Information was Exposed? 

According to the Ministry of Foreign Affairs, the information compromised during the National Diplomatic Academy data breach included: 
  • User IDs 
  • Names 
  • Email addresses 
  • Encrypted passwords 
The ministry emphasized that several categories of sensitive information were not exposed.  Its official notice stated:  "The personal information items involved in the leak include the ID, name, email, and encrypted password of the trainee in the Korea National Diplomatic Academy's online education system."  The notice further clarified:  "Unique identification information, sensitive information, mobile phone numbers, home addresses, and photos were not included."  This means national identification numbers, photographs, residential addresses, phone numbers, and other sensitive personal data were not part of the compromised dataset, according to the ministry. 
  • ✇ASEC BLOG
  • June 2026 Security Issues in Korean & Global Financial Sector ATCP
    Statistics on Malware Distributed to the Financial Sector In the June threat analysis for the financial sector, phishing was the most prevalent attack method in Attack Stage 1, while droppers/downloaders (distribution tools that download additional malware) were the most prevalent in Attack Stage 2. Infostealers were identified in the third attack stage, indicating that multi-stage […]
     

June 2026 Security Issues in Korean & Global Financial Sector

Por:ATCP
15 de Julho de 2026, 12:00
Statistics on Malware Distributed to the Financial Sector In the June threat analysis for the financial sector, phishing was the most prevalent attack method in Attack Stage 1, while droppers/downloaders (distribution tools that download additional malware) were the most prevalent in Attack Stage 2. Infostealers were identified in the third attack stage, indicating that multi-stage […]
  • ✇ASEC BLOG
  • June 2026 Dark Web Breach Incident Trend Report ATCP
    Note The June 2026 Dark Web Breach Incident Trend Report is based on major data breach cases posted on the deep web and dark web forums. Due to the nature of some sources, it was difficult to fully verify the accuracy of certain information, so the report includes content that requires further verification. Major Issue […]
     

June 2026 Dark Web Breach Incident Trend Report

Por:ATCP
8 de Julho de 2026, 12:00
Note The June 2026 Dark Web Breach Incident Trend Report is based on major data breach cases posted on the deep web and dark web forums. Due to the nature of some sources, it was difficult to fully verify the accuracy of certain information, so the report includes content that requires further verification. Major Issue […]
❌
❌