As cited
Copy frozen at (site build).
threat intel
DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors
Rapid7 Labs identified a sophisticated Linux toolkit attributed with medium confidence to North Korean APTs targeting South Korean media and automotive sectors since mid-2025. The campaign deploys a HAProxy-based backdoor named ted, trojanized system daemons (crond, agetty, atd, sshd, polkitd), and curlRAT, a curl-based remote access tool that monitors HAProxy health and exfiltrates credentials. The ted backdoor integrates as a custom HAProxy filter to intercept HTTP traffic, inject malicious scripts into web responses for selected victims, steal session cookies, and scrub connection logs to evade detection.
Why it matters: Organizations running HAProxy, crond, or exposed groupware portals in South Korea face immediate risk from undetectable credential theft and long-term surveillance; defenders must implement memory behavioral analysis, network correlation, and binary integrity checks on edge components, as log-only monitoring cannot detect these implants.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors
Rapid7 Labs identified a sophisticated Linux toolkit attributed with medium confidence to North Korean APTs targeting South Korean media and automotive sectors since mid-2025. The campaign deploys a HAProxy-based backdoor named ted, trojanized system daemons (crond, agetty, atd, sshd, polkitd), and curlRAT, a curl-based remote access tool that monitors HAProxy health and exfiltrates credentials. The ted backdoor integrates as a custom HAProxy filter to intercept HTTP traffic, inject malicious scripts into web responses for selected victims, steal session cookies, and scrub connection logs to evade detection.
Why it matters: Organizations running HAProxy, crond, or exposed groupware portals in South Korea face immediate risk from undetectable credential theft and long-term surveillance; defenders must implement memory behavioral analysis, network correlation, and binary integrity checks on edge components, as log-only monitoring cannot detect these implants.
- Source published
- First seen by Cybersecurity Tracker