DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors (opens in a new tab)
Why readA DPRK Linux toolkit that compiles a backdoor into the victim's own HAProxy 2.8.12 build and uses its filter API, memory pools and event scheduler to hide, alongside trojanized crond, agetty, atd, sshd and polkitd.
Rapid7 Labs documents a previously undocumented Linux framework hitting South Korean automotive and media organisations: a "ted backdoor" built as part of the target's existing HAProxy 2.8.12 installation, an SSH keylogger, a curl-based RAT with a watchdog thread monitoring HAProxy health, and a stager. Because the backdoor lives inside the load balancer process and legitimate balancing continues normally, it intercepts traffic, injects scripts into web responses and harvests credentials with minimal detection. The integration depth is the finding: hunting this means examining HAProxy binaries and their filter chains against packaged versions, not looking for foreign processes.
Indicators12
- Hashes
4bb923eb040aa13ca8fd409c31ee4729c60ddff32e350efe1c5a4a9168a065f5c8c68e629bba773a10ac80012d10bf195db1b6d52faf60b4f32d6fd0c7c938e4d05d29a14c32ded4a9668357c08b6a9109739441ed4599bac2f8159028f772f71e4b25c8badfff95574e56d7384f3dbefea1bc36632c71e5a839803469ef60ac47595d36b2c50934ac109ade6df06e61feeea9d0bf6ae7396d28271baa51ae50df5169ce5d32a516865856f91abc50b3ecd427ea8330a4ff73618483e00b9b418f30b57928934ae67478d0e690c91d046e35a638da098d02922a4a88a0fdb66c72e70936f0dbe459142a1d867617c35f8d0cce5d18c6a49e1090a2a5adc8e558a8bfab4de81a1acb04aacdf757346946b0f5e30f0c9f402004016d0e425119c783f7d565b0465546027052b597af46eae3a199e7a91fcc2ab9363411473491307007a78d50a993cb174c685eba96eb442c9507e38fd9d8e5dffc712f613ec110