← Back to feed
Threat Actors & CampaignsEmerging1 sourceSep 4, 2026 · 12:00via Rapid7 Blog

DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors

Brief

Overview

A new Linux toolkit, identified by Rapid7 Labs, has been targeting organizations across South Korea’s automotive and media industries with minimal detection. The campaign made use of a HAProxy instance named “ted backdoor”, alongside trojanized versions of crond, agetty, atd, sshd, and polkitd.

This previously undocumented framework enabled threat actors to execute remote commands on compromised servers, inject malicious scripts into web traffic, perform credential harvesting, and engage in long-term surveillance.

The standout feature of this toolkit is its depth of integration with the target environment. The ted backdoor is compiled as part of the victim’s existing HAProxy version 2.

  • 12.
Read more on Rapid7 Blog