North Korean Hackers Embed Linux Backdoor Inside HAProxy to Spy on South Korea
A North Korea-linked threat actor, assessed with medium confidence, has deployed a Linux surveillance toolkit targeting South Korean sectors, according to a Rapid7 report published on September 4, 2026. The campaign uses a backdoor called 'ted' embedded directly inside HAProxy 2.8.12 as an internal filter, allowing attackers to intercept, tamper with, and exfiltrate web traffic while hiding activity from logs and counters. A second tool, curlRAT, provides persistent remote shell access and additional payload delivery under disguised process names, while an SSH keylogger harvests plaintext credentials from administrators. The attackers operate with root-level privileges on internet-facing Linux servers, replacing system binaries such as cron and OpenSSH and clearing logs to cover their tracks. Defenders are advised to verify binary integrity against known-good baselines, rely on independent network logs such as upstream proxies and TAPs, and rebuild compromised systems after preserving forensic evidence.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in