NORTH Korean-aligned threat actors have been using a new Linux-based espionage toolkit in attacks focused on automotive and media organisations in South Korea, according to Rapid7. The framework centres on a backdoor embedded in HAProxy, named the ted backdoor, which is paired with trojanised variants of common utilities such as agetty, atd, crond, polkitd and sshd.
The operation supports remote command execution, credential harvesting and script injection into web traffic, enabling long‑term surveillance while blending malicious activity with normal traffic.
Rapid7 describes a multi-stage infection: initial access is gained via exploitation of a Groupware login portal; an SSH keylogger that also acts as a staging server is used to harvest credentials and facilitate lateral movement. The stager checks for the presence of crond or HAProxy and then deploys CurlRAT, retrieving components from its data section or an edge web server, while the ted backdoor is dropped onto the HAProxy load balancer.
CurlRAT polls the C2 every 12 hours, can decrypt and execute commands, write new payloads to disk and provide a full interactive PTY shell. The ted backdoor is a custom HAProxy plugin compiled into the HAProxy source, capable of intercepting and injecting HTTP traffic, executing C2 tasks and achieving persistence.
Observed activity also includes domain use patterns and watering-hole techniques previously linked to APT37 and Lazarus, with the campaign timeframe overlapping Operation SyncHole, suggesting a North Korean attribution.