securityonline.info 10 Sept 2026, 08:01 UTC

Stealthy Ted Backdoor Hijacks HAProxy to Spy on South Korea

Stealthy Ted Backdoor Hijacks HAProxy to Spy on South Korea
CyberSIXT Evidence Panel Source marked as original reporting

RAPID 7 researchers have identified a stealthy Linux backdoor, dubbed the ted backdoor, that hides inside a modified HAProxy load balancer to spy on South Korean organisations. The tool is designed to run as a plugin for HAProxy version 2.8.12, allowing the load balancer to continue handling traffic while the attacker monitors requests and extracts sensitive data. In the observed campaign, targeting focused on South Korea’s media and automotive sectors, with activity dating back to the early part of 2025.

In addition to the backdoor, operators deployed a curlRAT, a keylogger, and a stager, all designed to operate beneath the radar by trojanising trusted system daemons such as crond, agetty, atd, sshd and polkitd.

Mechanically, the ted backdoor hooks into HAProxy’s HTTP parser to inspect and log high‑value traffic, including login pages and admin panels, and it can steal session cookies from passing traffic. Victim selection is based on client IP, with malicious scripts injected into the page for chosen targets. Crucially, the campaign’s command and control traffic is contained entirely within the load balancer, meaning no backend server logs show attacker activity.

The stager checks for HAProxy or cron before dropping a backdoored crond binary, timestomps files, and clears logs. curlRAT operates via crond with two threads—one for HTTPS C2 communication using libcurl, and another for health reporting to the operator—enabling command execution, reverse shells and interactive PTY sessions.

Attribution is given with medium confidence to DPRK APTs (linked to APT37 in ThreatFox and related activity), with ties to prior Lazarus operations. Rapid7 emphasises that further evidence is needed for a more definitive assessment. Two confirmed victims ran edge web servers exposing ports 80, 443 and 25, with 443 hosting a Groupware login portal.

The report advocates treating edge devices with the same rigour as core servers, enabling independent network correlation, binary integrity checks, and monitoring for unexpected outbound HTTPS traffic to unfamiliar domains.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline