DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors
A previously undocumented Linux toolkit has been targeting South Korean automotive and media organizations with minimal detection since early 2025. The campaign employs a HAProxy instance called ted backdoor, compiled within the victim's existing HAProxy version 2.8.12, alongside trojanized versions of crond, agetty, atd, sshd, and polkitd. This sophisticated framework enables remote command execution, malicious script injection into web traffic, credential harvesting, and long-term surveillance. The ted backdoor uses HAProxy's native filter API and internal structures to intercept SSL-decrypted HTTP traffic while maintaining legitimate load balancing operations. Operating alongside are an SSH keylogger, a curl-based RAT with HAProxy health monitoring capabilities, and a deployment stager. The toolkit is attributed with medium confidence to DPRK APTs based on targeting patterns, simple XOR-based encryption schemes, custom substitution ciphers, and C2 infrastructure associated with APT37.
AI Analysis
Technical Summary
This threat involves a previously undocumented Linux toolkit deployed by DPRK-linked APT37 targeting South Korean automotive and media sectors. The core component is a ted backdoor implemented as a trojanized HAProxy 2.8.12 instance, which uses HAProxy's native filter API and internal structures to intercept SSL-decrypted HTTP traffic without disrupting legitimate load balancing functions. Additional trojanized system binaries (crond, agetty, atd, sshd, polkitd) support remote command execution, malicious script injection, and credential harvesting. The toolkit also includes an SSH keylogger, a curl-based RAT with HAProxy health monitoring, and a deployment stager. Attribution to APT37 is supported by medium confidence due to XOR-based encryption, custom ciphers, and known C2 infrastructure. No known exploits in the wild or patches are indicated.
Potential Impact
The malware enables attackers to execute remote commands, inject malicious scripts into web traffic, harvest credentials, and conduct long-term surveillance on compromised Linux systems. By trojanizing critical system binaries and HAProxy, it maintains persistence and stealth while intercepting sensitive SSL-decrypted traffic. This compromises confidentiality, integrity, and availability of targeted systems in the South Korean automotive and media sectors.
Mitigation Recommendations
No official patches or vendor advisories are available for this threat. Organizations should monitor for unusual HAProxy 2.8.12 instances and trojanized system binaries, especially crond, agetty, atd, sshd, and polkitd. Incident response should focus on identifying and removing the ted backdoor and associated components. Given the complexity and stealth of this toolkit, enhanced endpoint detection and network monitoring tailored to these indicators are recommended. Patch status is not yet confirmed—check vendor advisories for updates.
Affected Countries
South Korea
Indicators of Compromise
- hash: 5db1b6d52faf60b4f32d6fd0c7c938e4d05d29a14c32ded4a9668357c08b6a91
- hash: 09739441ed4599bac2f8159028f772f71e4b25c8badfff95574e56d7384f3dbe
- hash: fea1bc36632c71e5a839803469ef60ac47595d36b2c50934ac109ade6df06e61
- hash: 83f7d565b0465546027052b597af46eae3a199e7a91fcc2ab936341147349130
- hash: 7007a78d50a993cb174c685eba96eb442c9507e38fd9d8e5dffc712f613ec110
- hash: 6cf1b5e92a9c0756f597a5ddefb38eba32961c52efac7ab2a0aa52c639a8fc53
- hash: ed72f4cd8d467b5c5d95ae6aeca4aaeea14d79565d379c1ca5871a714727be16
- hash: feeea9d0bf6ae7396d28271baa51ae50df5169ce5d32a516865856f91abc50b3
- hash: d53c760c23b4405eb04ad0f20ead375440344b3bdf1fb7854ed12e40d155eabe
- hash: 2f02b09d61d432134e994ad671258f523bbf289ae6091fd4eae192c60bd51b6f
- hash: 8f30b57928934ae67478d0e690c91d046e35a638da098d02922a4a88a0fdb66c
- hash: a1d8af3a6acb731f07f72040eccb3450c1c83d40e29f736c2a63d35388660be4
- hash: 12810854c8b2c391b23e2e18b013e873d0369b0637aa3cf993136c07188ba3b8
- hash: 009a1e2d7a582a24e50cf2ffc2a005482c8e38f22bf5ed416053855f8d054e1e
- hash: 4bb923eb040aa13ca8fd409c31ee4729c60ddff32e350efe1c5a4a9168a065f5
- hash: 94630b96f628c96a6bff7904b40ffc9ad67c86f8a4ff6080c3b524831c93f402
- hash: 72e70936f0dbe459142a1d867617c35f8d0cce5d18c6a49e1090a2a5adc8e558
- hash: a8bfab4de81a1acb04aacdf757346946b0f5e30f0c9f402004016d0e425119c7
- domain: img.monderhouse.space
- domain: img.smartnords.site
- domain: img.darklights.store
- domain: img.responsive.pstatic.autos
- domain: img.socialteams.store
- domain: img.worksongo.store
- hash: c8c68e629bba773a10ac80012d10bf19
- hash: ecd427ea8330a4ff73618483e00b9b41
DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors
Description
A previously undocumented Linux toolkit has been targeting South Korean automotive and media organizations with minimal detection since early 2025. The campaign employs a HAProxy instance called ted backdoor, compiled within the victim's existing HAProxy version 2.8.12, alongside trojanized versions of crond, agetty, atd, sshd, and polkitd. This sophisticated framework enables remote command execution, malicious script injection into web traffic, credential harvesting, and long-term surveillance. The ted backdoor uses HAProxy's native filter API and internal structures to intercept SSL-decrypted HTTP traffic while maintaining legitimate load balancing operations. Operating alongside are an SSH keylogger, a curl-based RAT with HAProxy health monitoring capabilities, and a deployment stager. The toolkit is attributed with medium confidence to DPRK APTs based on targeting patterns, simple XOR-based encryption schemes, custom substitution ciphers, and C2 infrastructure associated with APT37.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This threat involves a previously undocumented Linux toolkit deployed by DPRK-linked APT37 targeting South Korean automotive and media sectors. The core component is a ted backdoor implemented as a trojanized HAProxy 2.8.12 instance, which uses HAProxy's native filter API and internal structures to intercept SSL-decrypted HTTP traffic without disrupting legitimate load balancing functions. Additional trojanized system binaries (crond, agetty, atd, sshd, polkitd) support remote command execution, malicious script injection, and credential harvesting. The toolkit also includes an SSH keylogger, a curl-based RAT with HAProxy health monitoring, and a deployment stager. Attribution to APT37 is supported by medium confidence due to XOR-based encryption, custom ciphers, and known C2 infrastructure. No known exploits in the wild or patches are indicated.
Potential Impact
The malware enables attackers to execute remote commands, inject malicious scripts into web traffic, harvest credentials, and conduct long-term surveillance on compromised Linux systems. By trojanizing critical system binaries and HAProxy, it maintains persistence and stealth while intercepting sensitive SSL-decrypted traffic. This compromises confidentiality, integrity, and availability of targeted systems in the South Korean automotive and media sectors.
Defensive Guidance
No official patches or vendor advisories are available for this threat. Organizations should monitor for unusual HAProxy 2.8.12 instances and trojanized system binaries, especially crond, agetty, atd, sshd, and polkitd. Incident response should focus on identifying and removing the ted backdoor and associated components. Given the complexity and stealth of this toolkit, enhanced endpoint detection and network monitoring tailored to these indicators are recommended. Patch status is not yet confirmed—check vendor advisories for updates.
Affected Countries
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.rapid7.com/blog/post/tr-dprk-apts-ted-backdoor-curlrat-target-south-korean-media-automotive-sectors"]
- Adversary
- APT37
- Pulse Id
- 6a9af7a5158ae188847551b5
- Threat Score
- null
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hash5db1b6d52faf60b4f32d6fd0c7c938e4d05d29a14c32ded4a9668357c08b6a91 | — | |
hash09739441ed4599bac2f8159028f772f71e4b25c8badfff95574e56d7384f3dbe | — | |
hashfea1bc36632c71e5a839803469ef60ac47595d36b2c50934ac109ade6df06e61 | — | |
hash83f7d565b0465546027052b597af46eae3a199e7a91fcc2ab936341147349130 | — | |
hash7007a78d50a993cb174c685eba96eb442c9507e38fd9d8e5dffc712f613ec110 | — | |
hash6cf1b5e92a9c0756f597a5ddefb38eba32961c52efac7ab2a0aa52c639a8fc53 | — | |
hashed72f4cd8d467b5c5d95ae6aeca4aaeea14d79565d379c1ca5871a714727be16 | — | |
hashfeeea9d0bf6ae7396d28271baa51ae50df5169ce5d32a516865856f91abc50b3 | — | |
hashd53c760c23b4405eb04ad0f20ead375440344b3bdf1fb7854ed12e40d155eabe | — | |
hash2f02b09d61d432134e994ad671258f523bbf289ae6091fd4eae192c60bd51b6f | — | |
hash8f30b57928934ae67478d0e690c91d046e35a638da098d02922a4a88a0fdb66c | — | |
hasha1d8af3a6acb731f07f72040eccb3450c1c83d40e29f736c2a63d35388660be4 | — | |
hash12810854c8b2c391b23e2e18b013e873d0369b0637aa3cf993136c07188ba3b8 | — | |
hash009a1e2d7a582a24e50cf2ffc2a005482c8e38f22bf5ed416053855f8d054e1e | — | |
hash4bb923eb040aa13ca8fd409c31ee4729c60ddff32e350efe1c5a4a9168a065f5 | — | |
hash94630b96f628c96a6bff7904b40ffc9ad67c86f8a4ff6080c3b524831c93f402 | — | |
hash72e70936f0dbe459142a1d867617c35f8d0cce5d18c6a49e1090a2a5adc8e558 | — | |
hasha8bfab4de81a1acb04aacdf757346946b0f5e30f0c9f402004016d0e425119c7 | — | |
hashc8c68e629bba773a10ac80012d10bf19 | — | |
hashecd427ea8330a4ff73618483e00b9b41 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainimg.monderhouse.space | — | |
domainimg.smartnords.site | — | |
domainimg.darklights.store | — | |
domainimg.responsive.pstatic.autos | — | |
domainimg.socialteams.store | — | |
domainimg.worksongo.store | — |
Threat ID: 6a9e9063acd9273b4963a740
Added to database: 09/07/2026, 10:22:27 UTC
Last enriched: 09/07/2026, 10:38:16 UTC
Last updated: 09/07/2026, 12:54:23 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.