CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5703

As cited

Copy frozen at (site build).

threat intel

DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors

Rapid7 Labs identified a sophisticated Linux toolkit attributed with medium confidence to North Korean APTs targeting South Korean media and automotive sectors since mid-2025. The campaign deploys a HAProxy-based backdoor named ted, trojanized system daemons (crond, agetty, atd, sshd, polkitd), and curlRAT, a curl-based remote access tool that monitors HAProxy health and exfiltrates credentials. The ted backdoor integrates as a custom HAProxy filter to intercept HTTP traffic, inject malicious scripts into web responses for selected victims, steal session cookies, and scrub connection logs to evade detection.

Why it matters: Organizations running HAProxy, crond, or exposed groupware portals in South Korea face immediate risk from undetectable credential theft and long-term surveillance; defenders must implement memory behavioral analysis, network correlation, and binary integrity checks on edge components, as log-only monitoring cannot detect these implants.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors

Rapid7 Labs identified a sophisticated Linux toolkit attributed with medium confidence to North Korean APTs targeting South Korean media and automotive sectors since mid-2025. The campaign deploys a HAProxy-based backdoor named ted, trojanized system daemons (crond, agetty, atd, sshd, polkitd), and curlRAT, a curl-based remote access tool that monitors HAProxy health and exfiltrates credentials. The ted backdoor integrates as a custom HAProxy filter to intercept HTTP traffic, inject malicious scripts into web responses for selected victims, steal session cookies, and scrub connection logs to evade detection.

Why it matters: Organizations running HAProxy, crond, or exposed groupware portals in South Korea face immediate risk from undetectable credential theft and long-term surveillance; defenders must implement memory behavioral analysis, network correlation, and binary integrity checks on edge components, as log-only monitoring cannot detect these implants.

VendorsJenkinsLinux
Actorslazarus groupkimsuky
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary