North Korea-allied threat actors have used a new Linux toolkit to attack automotive and media companies in South Korea, according to Rapid7.
The framework, designed for long-term monitoring, consists of a HAProxy instance called “ted backdoor” and trojanized versions of tools such as “agetty,” “atd,” “crond,” “polkitd,” and “sshd.”
The toolkit supports remote command execution, credential gathering, and script injection into web traffic, allowing attackers to silently spy on victims for extended periods of time.
According to Rapid7, the framework is deeply integrated into the target infrastructure The Ted Back Door is compiled as part of HAProxy version 2.8.12 running in the victim’s environment.
“It leverages its native filtering API, internal storage pools, an event scheduler, and process management infrastructure to intercept traffic and hide from monitoring while real load balancing traffic works as expected,” the cybersecurity company explains.
The toolkit has likely been in use since late 2024, when the first affected HAProxy iteration was released, and also uses a curl-based RAT, an SSH keylogger, and a stager.
The first access to an edge server was gained by exploiting a vulnerability in the groupware login portal. The SSH keylogger, which also serves as a staging server, was used to collect credentials and allowed for lateral transfer to internal systems.
“The stager checks whether either crond or HAProxy is present, only then deploys CurlRAT and retrieves it either from its data section or from the edge web server. In parallel, the ted backdoor is placed on the HAProxy load balancer,” explains Rapid7.
The backdoor establishes the C&C communications for data exfiltration, script injection, and command execution, and the balancer begins redirecting or serving malicious content to selected clients that browse the backdoor.
CurlRAT, the curl-based RAT used in the attacks, polls the C&C for commands every 12 hours. Based on this, it can decrypt and execute commands stored in its configuration, decode and write a new configuration payload to disk, and provide a fully interactive PTY shell.
The Ted Backdoor is a custom HAProxy plugin compiled to HAProxy source code and integrated directly into the balancer’s built-in HTTP parser. It can intercept and inject HTTP traffic, perform C&C tasks, and achieve persistence, among other things.
As part of the observed attacks, the threat actor leveraged domains registered under low-cost standard top-level domains (TLDs) and intruded payload delivery traffic into normal web browsing by impersonating Naver’s static content domain pstatic.net.
“Ted Backdoor and CurlRAT are designed to persist during long-term espionage operations, providing the ability to steal cookie sessions and credentials, redirect selected users, conduct drive-by download attacks, and hide evidence of the compromised page in a specific range of IPs to avoid detection,” notes Rapid7.
Attack artifacts recovered by the cybersecurity firm as well as the infrastructure used suggest watering hole techniques previously used by APT37 and Lazarus, and the campaign’s time frame overlaps with that of Operation SyncHole attributed to Lazarus last year, suggesting that a North Korean threat actor may also be behind this campaign.
Related: US disrupts Chinese hacking platform used in attacks on military and critical infrastructure
Related: USA and allies warn of Russian cyber attacks on routers of critical infrastructure
Related: EU targets Russian intelligence officers accused of conducting cyber espionage campaign
Related: Hackers linked to China and India both targeted the same Pakistani police force
