Key Facts

Rapid7 Labs identified a previously undocumented Linux toolkit targeting South Korean automotive and media organizations. Rapid7 attributes the activity to DPRK-aligned actors with medium confidence.

Technical Details

The toolkit combines a modified HAProxy instance called ted backdoor with trojanized Linux services, an SSH keylogger, a stager, and curlRAT. Rapid7 says the HAProxy component can intercept web traffic, steal session cookies, inject scripts, and receive command-and-control tasks.

Impact & Mitigation

Rapid7 describes long-term surveillance, credential harvesting, command execution, and selective web-content manipulation. Defenders should use the research’s indicators and investigate unexplained changes to HAProxy, cron, SSH, and other system-service binaries.

Sources

By Allan