B
今週中
北朝鮮に関連する攻撃者が、韓国の自動車およびメディア組織を標的とした新しいLinux用スパイウェアツールキットを導入しました
📌 一言でいうと
北朝鮮に関連する攻撃者が、韓国の自動車およびメディア組織を標的とした新しいLinux用スパイウェアツールキットを導入しました。このツールキットはHAProxy 2.8.12に「ted backdoor」を組み込み、agettyやsshdなどの正規ツールをトロイ木馬化して、長期的な監視とデータ窃取を行います。リモートコマンド実行や認証情報の収集、Webトラフィックへのスクリプト注入などの機能を備えており、検知を回避しながら深くインフラに統合される設計となっています。
🔍該当判定
- 自社でLinuxサーバーを運用している
- ロードバランサーとして「HAProxy」を利用している
- HAProxyのバージョンが 2.8.12 である
上記いずれにも該当しない → 静観でOK
✅該当時の対応
HAProxyおよび主要なシステムバイナリ(sshd, crond, agetty等)の整合性チェックを実施し、不審な変更がないか確認してください。また、不審なアウトバウンド通信や特権アカウントの異常な挙動を監視してください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】北朝鮮系アクターによるLinux向け新スパイウェアツールキットへの対応について
お疲れさまです。北朝鮮に関連する攻撃者が使用する新しいLinux用ツールキットに関する情報共有です。
■ 概要
HAProxy 2.8.12に「ted backdoor」を組み込み、さらにagetty, atd, crond, polkitd, sshdなどのシステムツールをトロイ木馬化して潜伏する高度なスパイウェアです。正規のロードバランシング機能を維持しつつ、トラフィックの傍受や認証情報の窃取、リモートコマンド実行を行います。
■ 影響範囲
- Linux環境でHAProxy 2.8.12を使用しているサーバー
- トロイ木馬化されたシステムバイナリ(sshd, crond等)が動作している環境
■ 対応手順
1. HAProxyのバージョンおよびバイナリの整合性を確認し、不正な変更(ted backdoorの混入)がないか検証してください。
2. /usr/sbin/ 等にある主要システムバイナリのハッシュ値を、既知のクリーンなイメージと比較してください。
3. 外部への不審なC2通信(curlベースのRAT等)が発生していないかネットワークログを確認してください。
■ 参考情報
- Rapid7 Report
対応優先度: 高
対応期限: 速やかに確認
お疲れさまです。北朝鮮に関連する攻撃者が使用する新しいLinux用ツールキットに関する情報共有です。
■ 概要
HAProxy 2.8.12に「ted backdoor」を組み込み、さらにagetty, atd, crond, polkitd, sshdなどのシステムツールをトロイ木馬化して潜伏する高度なスパイウェアです。正規のロードバランシング機能を維持しつつ、トラフィックの傍受や認証情報の窃取、リモートコマンド実行を行います。
■ 影響範囲
- Linux環境でHAProxy 2.8.12を使用しているサーバー
- トロイ木馬化されたシステムバイナリ(sshd, crond等)が動作している環境
■ 対応手順
1. HAProxyのバージョンおよびバイナリの整合性を確認し、不正な変更(ted backdoorの混入)がないか検証してください。
2. /usr/sbin/ 等にある主要システムバイナリのハッシュ値を、既知のクリーンなイメージと比較してください。
3. 外部への不審なC2通信(curlベースのRAT等)が発生していないかネットワークログを確認してください。
■ 参考情報
- Rapid7 Report
対応優先度: 高
対応期限: 速やかに確認
Subject: [Security Alert] New Linux Espionage Toolkit by North Korean Actors
Dear IT/Security Team,
We are sharing information regarding a new Linux-based espionage toolkit attributed to North Korean threat actors.
■ Overview
The toolkit is designed for long-term surveillance and deeply integrates a 'ted backdoor' into HAProxy version 2.8.12. It also employs trojanized versions of standard Linux utilities (e.g., sshd, crond, agetty) to intercept traffic, harvest credentials, and execute remote commands while evading detection.
■ Scope
- Servers running HAProxy v2.8.12
- Linux environments where system binaries may have been replaced by trojanized versions.
■ Recommended Actions
1. Verify the integrity of HAProxy binaries and check for unauthorized modifications.
2. Perform hash comparisons of critical system binaries (/usr/sbin/sshd, etc.) against known clean baselines.
3. Monitor network logs for suspicious outbound traffic associated with curl-based RATs or unauthorized SSH activity.
■ Reference
- Rapid7 Report
Priority: High
Deadline: Immediate review
Dear IT/Security Team,
We are sharing information regarding a new Linux-based espionage toolkit attributed to North Korean threat actors.
■ Overview
The toolkit is designed for long-term surveillance and deeply integrates a 'ted backdoor' into HAProxy version 2.8.12. It also employs trojanized versions of standard Linux utilities (e.g., sshd, crond, agetty) to intercept traffic, harvest credentials, and execute remote commands while evading detection.
■ Scope
- Servers running HAProxy v2.8.12
- Linux environments where system binaries may have been replaced by trojanized versions.
■ Recommended Actions
1. Verify the integrity of HAProxy binaries and check for unauthorized modifications.
2. Perform hash comparisons of critical system binaries (/usr/sbin/sshd, etc.) against known clean baselines.
3. Monitor network logs for suspicious outbound traffic associated with curl-based RATs or unauthorized SSH activity.
■ Reference
- Rapid7 Report
Priority: High
Deadline: Immediate review