Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors

0
Medium
Published: 09/04/2026 (09/04/2026, 16:53:57 UTC)
Source: AlienVault OTX General

Description

A previously undocumented Linux toolkit has been targeting South Korean automotive and media organizations with minimal detection since early 2025. The campaign employs a HAProxy instance called ted backdoor, compiled within the victim's existing HAProxy version 2.8.12, alongside trojanized versions of crond, agetty, atd, sshd, and polkitd. This sophisticated framework enables remote command execution, malicious script injection into web traffic, credential harvesting, and long-term surveillance. The ted backdoor uses HAProxy's native filter API and internal structures to intercept SSL-decrypted HTTP traffic while maintaining legitimate load balancing operations. Operating alongside are an SSH keylogger, a curl-based RAT with HAProxy health monitoring capabilities, and a deployment stager. The toolkit is attributed with medium confidence to DPRK APTs based on targeting patterns, simple XOR-based encryption schemes, custom substitution ciphers, and C2 infrastructure associated with APT37.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/07/2026, 10:38:16 UTC

Technical Analysis

This threat involves a previously undocumented Linux toolkit deployed by DPRK-linked APT37 targeting South Korean automotive and media sectors. The core component is a ted backdoor implemented as a trojanized HAProxy 2.8.12 instance, which uses HAProxy's native filter API and internal structures to intercept SSL-decrypted HTTP traffic without disrupting legitimate load balancing functions. Additional trojanized system binaries (crond, agetty, atd, sshd, polkitd) support remote command execution, malicious script injection, and credential harvesting. The toolkit also includes an SSH keylogger, a curl-based RAT with HAProxy health monitoring, and a deployment stager. Attribution to APT37 is supported by medium confidence due to XOR-based encryption, custom ciphers, and known C2 infrastructure. No known exploits in the wild or patches are indicated.

Potential Impact

The malware enables attackers to execute remote commands, inject malicious scripts into web traffic, harvest credentials, and conduct long-term surveillance on compromised Linux systems. By trojanizing critical system binaries and HAProxy, it maintains persistence and stealth while intercepting sensitive SSL-decrypted traffic. This compromises confidentiality, integrity, and availability of targeted systems in the South Korean automotive and media sectors.

Defensive Guidance

No official patches or vendor advisories are available for this threat. Organizations should monitor for unusual HAProxy 2.8.12 instances and trojanized system binaries, especially crond, agetty, atd, sshd, and polkitd. Incident response should focus on identifying and removing the ted backdoor and associated components. Given the complexity and stealth of this toolkit, enhanced endpoint detection and network monitoring tailored to these indicators are recommended. Patch status is not yet confirmed—check vendor advisories for updates.

Affected Countries

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.rapid7.com/blog/post/tr-dprk-apts-ted-backdoor-curlrat-target-south-korean-media-automotive-sectors"]
Adversary
APT37
Pulse Id
6a9af7a5158ae188847551b5
Threat Score
null

Indicators of Compromise

Hash

ValueDescriptionCopy
hash5db1b6d52faf60b4f32d6fd0c7c938e4d05d29a14c32ded4a9668357c08b6a91
hash09739441ed4599bac2f8159028f772f71e4b25c8badfff95574e56d7384f3dbe
hashfea1bc36632c71e5a839803469ef60ac47595d36b2c50934ac109ade6df06e61
hash83f7d565b0465546027052b597af46eae3a199e7a91fcc2ab936341147349130
hash7007a78d50a993cb174c685eba96eb442c9507e38fd9d8e5dffc712f613ec110
hash6cf1b5e92a9c0756f597a5ddefb38eba32961c52efac7ab2a0aa52c639a8fc53
hashed72f4cd8d467b5c5d95ae6aeca4aaeea14d79565d379c1ca5871a714727be16
hashfeeea9d0bf6ae7396d28271baa51ae50df5169ce5d32a516865856f91abc50b3
hashd53c760c23b4405eb04ad0f20ead375440344b3bdf1fb7854ed12e40d155eabe
hash2f02b09d61d432134e994ad671258f523bbf289ae6091fd4eae192c60bd51b6f
hash8f30b57928934ae67478d0e690c91d046e35a638da098d02922a4a88a0fdb66c
hasha1d8af3a6acb731f07f72040eccb3450c1c83d40e29f736c2a63d35388660be4
hash12810854c8b2c391b23e2e18b013e873d0369b0637aa3cf993136c07188ba3b8
hash009a1e2d7a582a24e50cf2ffc2a005482c8e38f22bf5ed416053855f8d054e1e
hash4bb923eb040aa13ca8fd409c31ee4729c60ddff32e350efe1c5a4a9168a065f5
hash94630b96f628c96a6bff7904b40ffc9ad67c86f8a4ff6080c3b524831c93f402
hash72e70936f0dbe459142a1d867617c35f8d0cce5d18c6a49e1090a2a5adc8e558
hasha8bfab4de81a1acb04aacdf757346946b0f5e30f0c9f402004016d0e425119c7
hashc8c68e629bba773a10ac80012d10bf19
hashecd427ea8330a4ff73618483e00b9b41

Domain

ValueDescriptionCopy
domainimg.monderhouse.space
domainimg.smartnords.site
domainimg.darklights.store
domainimg.responsive.pstatic.autos
domainimg.socialteams.store
domainimg.worksongo.store

Threat ID: 6a9e9063acd9273b4963a740

Added to database: 09/07/2026, 10:22:27 UTC

Last enriched: 09/07/2026, 10:38:16 UTC

Last updated: 09/07/2026, 12:54:23 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses