threat_intelligence535 wordsRead on Arc Codex

North Korean Hackers Deploy New Linux Espionage Toolkit

North Korea-aligned threat actors have been using a new Linux toolkit in attacks targeting automotive and media organizations in South Korea, Rapid7 reports. Designed for long-term surveillance, the framework consists of a HAProxy instance called ‘ted backdoor’ and trojanized versions of tools such as ‘agetty’, ‘atd’, ‘crond’, ‘polkitd’, and ‘sshd’. The toolkit supports remote command execution, credential harvesting, and script injection into web traffic, enabling attackers to spy on victims for long periods of time without detection. According to Rapid7, the framework is deeply integrated within the target infrastructure, with the ted backdoor being compiled as part of the HAProxy version 2.8.12 running on the victim’s environment. “It uses its native filter API, internal memory pools, event scheduler, and process management infrastructure to intercept traffic and hide from monitoring, while genuine load balancing traffic operates as expected,” the cybersecurity firm explains. Likely in use since late 2024, when the first involved HAProxy iteration was released, the toolkit also uses a curl-based RAT, an SSH keylogger, and a stager. Initial access to an edge server was obtained through the exploitation of a Groupware login portal vulnerability. The SSH keylogger, which also serves as a staging server, was used for credential harvesting, enabling lateral movement to internal systems. “The stager checks for the presence of either crond or HAProxy, and only then deploys CurlRAT, retrieving it either from its data section or the edge web server. In parallel, the ted backdoor is dropped onto the HAProxy load balancer,” Rapid7 explains. The backdoor establishes C&C communication for data exfiltration, script injection, and command execution, and the balancer starts redirecting or serving malicious content to selected clients browsing through it. CurlRAT, the curl-based RAT deployed in the attacks, polls the C&C every 12 hours for commands. Based on these, it can decrypt and execute commands stored in its configuration, decode and write a new config payload to disk, and deploy a full interactive PTY shell. The ted backdoor is a custom HAProxy plugin compiled within the HAProxy source code, directly hooked into the balancer’s built-in HTTP parser. It can intercept and inject HTTP traffic, execute C&C tasks, and achieve persistence, among others. As part of the observed attacks, the threat actor used domains registered under low-cost commodity top-level domains (TLDs) and blended the payload delivery traffic into normal web browsing, mimicking Naver’s pstatic.net static content domain. “Ted backdoor and curlRAT were designed to persist during long-term espionage operations with the ability to steal cookie sessions, credentials, redirect selected users, conduct drive-by download attacks, and hide evidence of the tampered page to a specific range of IPs to evade detection,” Rapid7 notes. Attack artifacts recovered by the cybersecurity firm, along with the infrastructure used, point to watering-hole techniques previously used by APT37 and Lazarus, and the campaign timeframe overlaps with that of Operation SyncHole, attributed to Lazarus last year, which suggests that a North Korean threat actor might be behind this campaign as well. Related: US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks Related: US, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers Related: EU Targets Russian Intelligence Officers Accused of Running Cyber Spying Campaign Related: China, India-Linked Hackers Both Targeted Same Pakistani Police Force

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.