North Korea-Linked Hackers Deploy New Linux Espionage Toolkit With Backdoor Compiled Into HAProxy Against South Korean Targets
Rapid7-documented Linux espionage toolkit attributed with medium confidence to North Korean state actors hit South Korean automotive and media organizations, using a backdoor ('ted') compiled directly into victims' HAProxy 2.8.12, trojanized system binaries,…
Rapid7 documented a previously undocumented Linux espionage toolkit targeting South Korean automotive and media organizations. Its centerpiece is a custom backdoor ('ted') compiled directly into victims' HAProxy 2.8.12 — hooked into the native HTTP parser and using the filter API, memory pools, and scheduler — which intercepts HTTP traffic, receives C2 commands hidden in requests to a fake image path (/favorite_list_2x_m500_ico.jpg), stores them in a named pipe, and erases traces from logs and counters while load balancing continues normally. The toolkit also trojanizes system binaries (agetty, atd, crond, polkitd, sshd), includes an SSH keylogger, and runs CurlRAT, which performs virtualization checks, polls C&C every 12 hours, and can deploy an interactive PTY shell. Initial access came via an exploited Groupware login portal flaw, with harvested credentials enabling lateral movement to internal systems. The toolkit supports long-term surveillance, HTTP traffic interception/injection, and drive-by downloads, and can inject scripts or replace page content for selected victims based on IP, fingerprint, or a hidden Accept-Language credential, effectively turning the load balancer into a watering hole. Payload traffic mimics Naver's pstatic.net, low-cost TLD domains were used, and Security Affairs reports the command domains have since gone dark. SecurityWeek reports the toolkit has likely been in use since late 2024. On attribution, the sources converge on North Korean involvement but frame it differently: SecurityWeek says infrastructure and artifacts overlap Lazarus's Operation SyncHole and prior APT37 watering-hole activity, suggesting Lazarus or APT37 involvement, while Security Affairs describes medium-confidence attribution toward North Korean state actors with infrastructure overlapping APT37 indicators and traits shared with a concurrent Lazarus campaign.
- Rapid7 documented the campaign against South Korean automotive and media organizations (reports covered 2026-09-07 and 2026-09-08).
- Ted backdoor compiled into victims' HAProxy 2.8.12; SecurityWeek says it is hooked into HAProxy's native HTTP parser, while Security Affairs says it uses the filter API, memory pools, and scheduler; load balancing continues normally.
- C2 commands arrive hidden in HTTP requests to a fake image path, /favorite_list_2x_m500_ico.jpg, are stored in a named pipe, and logs/counters are scrubbed of traces (Security Affairs).
- Toolkit trojanizes system binaries: agetty, atd, crond, polkitd, and sshd, including an SSH keylogger used for credential harvesting.
- CurlRAT polls C&C every 12 hours, can deploy an interactive PTY shell (SecurityWeek), and includes anti-VM/virtualization checks (Security Affairs).
- Initial access via an exploited Groupware login portal flaw; harvested SSH-keylogger credentials enabled lateral movement to internal systems.
- Toolkit supports long-term surveillance, HTTP traffic interception/injection, and drive-by downloads; it can inject scripts or replace page content per victim IP, fingerprint, or hidden Accept-Language credential, creating watering-hole…
- Payload traffic mimics Naver's pstatic.net; low-cost TLD domains were used (SecurityWeek); the command domains have since gone dark (Security Affairs).
Coverage timelineoldest first · each row is one article
- · 9d agoNorth Korean Hackers Deploy New Linux Espionage Toolkit
SecurityWeek· 72
Rapid7 says North Korea-aligned actors use a new Linux espionage toolkit (ted HAProxy backdoor, CurlRAT) against South Korean automotive and media targets.