Suspected North Korean Hackers Deploy Ted Backdoor
Suspected North Korean hackers may have spied on South Korean organizations for years using trojanized Linux system services and an HAProxy backdoor. Rapid7 researchers discovered a previously unknown set of malicious tools. These tools infected networks within the South Korean automotive and media sectors. Furthermore, the attackers replaced legitimate files like crond, sshd, polkitd, agetty, and atd. Consequently, these malicious processes looked like standard Linux components.
The Ted Backdoor HAProxy Threat
The Ted Backdoor emerged as the primary element of this toolkit. The attackers embedded it directly into HAProxy version 2.8.12. Interestingly, this modified load balancer continued to route normal traffic. However, it simultaneously intercepted HTTP requests and stole cookies. It also gathered visitor data, executed commands, and altered web page content. Moreover, the operators could target specific users based on various parameters. They used IP addresses, subnets, user agents, page addresses, and referral sources. Subsequently, they silently modified server responses or injected malicious scripts.
Stealthy Command Execution
The commands arrived via specialized HTTP requests. These requests terminated inside HAProxy and never reached the internal server. As a result, standard application logs failed to record this malicious activity. Another key component was CurlRAT. The hackers injected its code into crond and other vital system services. This trojan supported command execution, file downloads, and shell access. Additionally, it gathered system information and communicated with command servers. The malware used standard HTTP or HTTPS protocols for this connection.
System Evasion and Credential Theft
The malware loader actively checked the Linux version and processor architecture. Next, it selected the appropriate file and replaced the real crond service. Furthermore, it assigned a fake timestamp matching the /usr/bin/ssh file. The modified sshd service functioned as an effective keystroke logger. The program collected plaintext user passwords and encrypted them. It used a custom algorithm and stored the data in the /var/lib/sshd directory. Meanwhile, the loader selectively deleted specific log entries. It removed lines mentioning tmp, wget, cron, and crond to hide the installation.
Attribution and Defense Strategies
Rapid7 analysts linked this campaign to North Korean threat groups with moderate confidence. Target selection and emulation of South Korean internet services suggest this origin. Encryption methods and command addresses also align with previous APT37 operations. However, researchers cannot yet identify the exact group or the initial compromise method. Vulnerable mail servers or corporate groupware portals likely provided the entry point. The earliest malware samples appeared on VirusTotal in mid-2025. Yet, the actual attacks probably began early that same year. Finally, administrators should review the Rapid7 analysis of the Ted Backdoor and CurlRAT for detailed guidance. Experts recommend verifying system file integrity and analyzing memory. Infected server logs alone cannot detect the Ted Backdoor.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.