www.darkreading.com 16 Sept 2026, 01:00 UTC

North Korean Hackers Hide TED Backdoor Inside HAProxy Appliances

North Korean Hackers Hide TED Backdoor Inside HAProxy Appliances
CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor

A likely North Korean advanced persistent threat (APT) group has targeted South Korean media and automotive organisations with a previously undocumented Linux toolkit called TED, according to an analysis by Rapid7 published on 15 September 2026. Rapid7 attributed the activity with medium confidence, citing the sectors targeted, simple obfuscation and command-and-control servers that overlap with infrastructure associated with APT37, also known as InkySquid, ScarCruft and Ricochet Chollima.

Some intrusions may have been active since early 2025. The media targets could provide access to unpublished reporting and journalist communications, while automotive victims may expose manufacturing technology and intellectual property, although the article does not identify the organisations affected.

The attackers reportedly first compromised an edge web or groupware server, then implanted TED into HAProxy, an open-source load balancer and reverse proxy. Because HAProxy handles SSL termination and sits in front of applications, the implant could access decrypted communications through the appliance’s filter API. Rapid7 said the activity included credential harvesting, redirecting selected users, drive-by downloads and altering log files to conceal operations.

TED reportedly creates no anomalous processes, unexpected outbound connections or normal HAProxy log entries; it sends command-and-control responses through raw TCP sockets and scrubs log counters. Rapid7 recommends treating load balancers and other network appliances as potential endpoints, checking library and binary integrity, auditing process memory and comparing device logs with independent, out-of-band records.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline