ZeroHour
Story · 1 source · 1 articlefirst updated ()

DPRK-linked 'ted' HAProxy backdoor and curlRAT target South Korean media and automotive sectors

highThreat actorexploited in the wildimportance 72
What's new: Initial merged summary consolidating four reports (Rapid7 2026-09-04, The Hacker News 2026-09-04, SecurityWeek 2026-09-07, Security Affairs 2026-09-08) — no prior summary existed. Flagged disagreements: campaign start (early 2025 per Rapid7 vs late 2024 per SecurityWeek); initial access (unconfirmed per Rapid7 vs Groupware login portal flaw per SecurityWeek); ted's hook mechanism (filter API vs…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Rapid7 has documented a previously undocumented Linux espionage toolkit, attributed with medium confidence to North Korean state-sponsored actors, targeting at least two South Korean automotive and media organizations. The toolkit includes a 'ted' backdoor…

Rapid7 Labs identified a stealthy Linux framework used against South Korean organizations in the automotive and media sectors (two organizations, per The Hacker News), in what is suspected to be long-term espionage. Its centerpiece is the 'ted' backdoor compiled directly into victims' HAProxy 2.8.12 binaries — using the filter API, memory pools, and scheduler per Rapid7/Security Affairs, or hooked into the native HTTP parser per SecurityWeek — while load balancing continues normally. The toolkit also trojanizes crond, sshd, agetty, atd, and polkitd, and includes an SSH keylogger storing credentials under /var/lib/sshd/. C2 commands arrive hidden in requests for a fake image path (/favorite_list_2x_m500_ico.jpg), are queued in a named pipe, and responses are disguised as HTTP/1.0 200 OK pages; ted hides C2 exchanges from backend logs and HAProxy statistics by decrementing connection counters and scrubs logs and bash history. The backdoor can inject malicious scripts into or replace served pages for selected victims — chosen by IP, browser fingerprint, or a hidden Accept-Language credential — creating a watering-hole loop with drive-by downloads. A companion curl-based RAT, curlRAT, checks root, profiles the OS, performs anti-VM checks, deploys backdoored crond, beacons on a default 12-hour schedule, and can deploy an interactive PTY shell. Rapid7 stresses ted requires prior code execution and is not a HAProxy flaw; the initial access vector is unconfirmed per Rapid7, though SecurityWeek reports exploitation of a Groupware login portal flaw with credential harvesting enabling lateral movement. Six C2 domains overlap APT37 indicators (via ThreatFox per Rapid7; maltrail per The Hacker News), and infrastructure shares traits with Lazarus's Operation SyncHole, suggesting Lazarus or APT37 involvement; payload traffic mimics Naver's pstatic.net and low-cost TLD domains were used. Rapid7 suspects activity since early 2025, while SecurityWeek reports likely use since late 2024; the command domains have since gone dark.

  • Ted backdoor compiled directly into victims' own HAProxy 2.8.12 binaries; requires prior code execution and is not a HAProxy vulnerability; load balancing continues normally.
  • Rapid7 and Security Affairs describe ted as using HAProxy's filter API, memory pools, and scheduler; SecurityWeek describes it as hooked into HAProxy's native HTTP parser.
  • C2 commands hidden in requests for fake image path /favorite_list_2x_m500_ico.jpg; commands stored in a named pipe; responses disguised as HTTP/1.0 200 OK pages; connection counters decremented and logs/bash history scrubbed.
  • Toolkit trojanizes crond, sshd, agetty, atd, and polkitd, and includes an SSH keylogger storing credentials under /var/lib/sshd/.
  • curlRAT checks root, profiles the OS, includes anti-VM/virtualization checks, beacons every 12 hours by default, deploys backdoored crond, and can deploy an interactive PTY shell.
  • Watering-hole capability: injects scripts or replaces page content for selected victims by IP, browser fingerprint, or hidden Accept-Language credential; enables drive-by downloads and long-term surveillance.
  • Targets: at least two South Korean organizations in the automotive and media sectors (per The Hacker News); suspected espionage.
  • Attribution: medium confidence to DPRK state-sponsored actors; six C2 domains overlap APT37 indicators (ThreatFox per Rapid7; maltrail per The Hacker News); infrastructure overlaps Lazarus's Operation SyncHole, suggesting Lazarus or APT37…

Coverage timeline

  1. · 13d ago
    Rapid7 Blog· 68
    DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors

    Rapid7 uncovered a DPRK-linked Linux toolkit using a HAProxy-embedded ted backdoor, SSH keylogger, and curlRAT against South Korean media and automotive firms.