ThreatPaper
State-SponsoredMalwareHigh

ted backdoor: North Korea hides a Linux implant inside victims' HAProxy load balancers

By Sethu Satheesh · 29 Sept 2026 · 11 min read

Threat Actor: DPRK-linked APT (medium confidence; APT37 / Lazarus overlap) · Target: South Korean automotive and media organizations

Source: www.rapid7.com


Executive Summary

Rapid7 Labs has documented a North Korea-linked Linux espionage toolkit whose signature move is to hide a backdoor inside the victim's own load balancer.1 The operators recompiled HAProxy 2.8.12 to include a custom plugin — the "ted" backdoor — that registers as a native HAProxy filter and lives entirely within the load balancer's own machinery: its filter API, memory pools, event scheduler and master-worker process model.23 Genuine load-balancing traffic continues to flow normally while the backdoor inspects it, which is precisely what makes the implant hard to see — it is not a rogue process next to HAProxy, it is HAProxy.2

The mechanism is unusually elegant for a backdoor. The ted filter hooks HAProxy's HTTP parser and inspects SSL-decrypted requests in the load balancer's parsed-HTTP (HTX) buffer; when a request matches a specific magic path — /favorite_list_2x_m500_ico.jpg — the plugin drops into command-and-control mode, extracting the source IP, Host, Referer and User-Agent and applying regex filters to identify traffic worth stealing.2 It can inject responses too, reshaping a reply to look like the requested file (setting Content-Type, adding a Content-Disposition filename, rewriting the body length).2 Command-and-control runs through the load balancer itself via named FIFO pipes and HAProxy's master-worker plumbing, so the attacker's command body never reaches a backend server — and the plugin scrubs HAProxy's own connection counters (beconn, feconn, actconn), using hardcoded offsets for the exact 2.8.12 build, to erase the traces its activity would otherwise leave in the load balancer's statistics.2

The load-balancer implant is only half of it. Rapid7 found a companion toolkit, CurlRAT, embedded in five trojanized Linux daemons — crond, agetty, atd, polkitd and sshd — each masquerading as its legitimate counterpart.2 The trojanized sshd is an SSH keylogger that captures plaintext credentials to an encrypted log; the others carry a curl-based RAT with six command modes (arbitrary command execution, config update, staged download, a privilege-escalating reverse shell, a system-info beacon, and an interactive PTY shell), plus a watchdog thread that checks HAProxy's health hourly.2 A stager profiles the host and drops the right trojanized binary, then sanitizes system logs to remove traces of its own installation.2

Rapid7 attributes the toolkit to a DPRK APT at medium confidence, noting the campaign's command-and-control infrastructure is associated with APT37 by ThreatFox and maltrail, and that the tradecraft overlaps with documented APT37 (Operation Code on Toast) and Lazarus (Operation SyncHole) activity against South Korean organizations.2 It stops short of a definitive call, stating that "further evidence is necessary to make a more definitive assessment."2 The targets are South Korean automotive and media organizations, with the earliest artifacts dating to mid-2025 — a patient, long-dwell surveillance operation rather than a smash-and-grab, which is exactly what a backdoor that reads a company's decrypted web traffic from inside its load balancer is built for.

Verification of Claims

  1. Claim: A backdoor ("ted") was compiled into victims' HAProxy 2.8.12 load balancers as a native plugin, with C2 routed through the load balancer itself. → Verified (per Rapid7) → Rapid7 documents the recompiled HAProxy 2.8.12 with a ted_plugin filter, its use of HAProxy's filter API, memory pools, scheduler and master-worker model, the magic-path trigger, response injection, counter-scrubbing evasion, and FIFO-pipe C2 through the load balancer.2

  2. Claim: The toolkit is North Korean. → Assessed, not confirmed → Rapid7 assesses medium-confidence DPRK attribution — the C2 is APT37-associated per ThreatFox/maltrail, and tradecraft overlaps APT37 and Lazarus operations against South Korea — but explicitly states "further evidence is necessary to make a more definitive assessment," and notes both APT37 and Lazarus (different DPRK agencies) conduct parallel South Korea espionage.2

  3. Claim: Initial access was gained by exploiting Groupware portal vulnerabilities. → Weak evidence → Rapid7's own analysis states the scenario "assumes the initial access is obtained by exploitation of CVEs related to the Groupware portal"; both victims exposed a Groupware login portal (443) and a mail server (25), consistent with documented Kimsuky tradecraft, but the exact entry point is unconfirmed.2

  4. Claim: The campaign targets South Korean automotive and media organizations. → Verified (per Rapid7) → Rapid7 identifies South Korean automotive and media sectors as the targets, with earliest VirusTotal uploads in mid-2025.2

Timeline

Date Actor Event Source
November 22, 2024 (HAProxy) HAProxy 2.8.12-0fdb194 released — the minimum compilation date for the trojanized build 2
Early 2025 onward DPRK APT (medium confidence) Campaign active against South Korean automotive and media organizations 2
Mid-2025 — Earliest VirusTotal uploads of the toolkit's samples 2
September 2026 Rapid7 Labs Publishes analysis of the ted backdoor and CurlRAT toolkit 23

Attack Anatomy

Initial access — assumed Groupware/mail-server exploitation

The exact entry point is unconfirmed; Rapid7's scenario assumes exploitation of CVEs in the victims' internet-facing Groupware portal (both victims exposed ports 80/443/25, with a Groupware login on 443 and a mail server on 25), consistent with documented DPRK/Kimsuky tradecraft against South Korean groupware vendors (T1190).2

Persistence in the load balancer — the ted plugin

The operators recompiled HAProxy 2.8.12 with a malicious ted_plugin, registering as a native filter that hooks the HTTP parser (T1505, T1554). It uses HAProxy's master-worker environment variables (HAPROXY_MWORKER_PP_READ/WRITE) to survive reloads.2

Traffic interception and injection

The filter inspects SSL-decrypted HTTP in HAProxy's HTX buffer (T1040), extracting source IP, Host, Referer and User-Agent and regex-filtering for high-value traffic; on a magic path (/favorite_list_2x_m500_ico.jpg) it enters C2 mode, and it can inject responses shaped to mimic a requested file.2 C2 runs through the load balancer via named FIFOs (/tmp/t[ID]_w.pipe) and the master-worker dispatcher, so command bodies never reach a backend (T1071.001).2

Companion RAT and credential theft

Five trojanized daemons (crond, agetty, atd, polkitd, sshd) carry CurlRAT and an SSH keylogger; the keylogger captures plaintext credentials to an encrypted log (T1056.001), and the RAT offers command execution, staged downloads, a privilege-escalating reverse shell, and an interactive PTY shell (T1059.004). C2 traffic is protected with XOR/substitution ciphers over Base64 (T1573.001).2

Evasion

The ted plugin scrubs HAProxy's internal connection counters using hardcoded 2.8.12 offsets; the stager sanitizes system logs (filtering tmp, wget, cron, crond) via /tmp/jasper-log (T1070), and crond is timestomped to match /usr/bin/ssh (T1070.006).2

Loading diagram...

Threat Actor Profile

  • Attacker: A DPRK-linked APT, assessed at medium confidence by Rapid7. The C2 infrastructure is associated with APT37 by ThreatFox and maltrail, and tradecraft overlaps both APT37 (Operation Code on Toast) and Lazarus (Operation SyncHole) — two groups under different DPRK agencies that both target South Korea.2
  • Attribution confidence: Medium. Rapid7 explicitly notes "further evidence is necessary to make a more definitive assessment," and does not resolve APT37 vs Lazarus.2
  • Objective: Long-dwell espionage — reading a target's decrypted web traffic from inside its load balancer, harvesting credentials, and maintaining stealthy remote access, against South Korean automotive and media organizations since at least early 2025.2
  • Sophistication: High. Building a backdoor as a native HAProxy plugin — abusing its filter API, memory pools, scheduler and master-worker model, and scrubbing its own build-specific counters — reflects deep knowledge of the target software and a deliberate choice to hide inside trusted infrastructure rather than beside it.2

MITRE ATT&CK techniques (verified on attack.mitre.org):

ID Technique
T1190 Exploit Public-Facing Application (assumed initial access)
T1505 Server Software Component
T1554 Compromise Host Software Binary
T1040 Network Sniffing
T1071.001 Application Layer Protocol: Web Protocols
T1056.001 Input Capture: Keylogging
T1059.004 Command and Scripting Interpreter: Unix Shell
T1573.001 Encrypted Channel: Symmetric Cryptography
T1070 Indicator Removal
T1070.006 Indicator Removal: Timestomp

Technical Indicators

ted_backdoor:
  - "malicious ted_plugin compiled into HAProxy 2.8.12 (native filter, HTX buffer interception)"
  - "magic path trigger: /favorite_list_2x_m500_ico.jpg"
  - "C2 via named FIFOs: /tmp/t[ID]_w.pipe; master-worker dispatcher; command body never reaches a backend"
  - "evasion: scrubs HAProxy beconn/feconn/actconn counters via hardcoded 2.8.12 offsets"
trojanized_daemons:
  - "crond (embeds CurlRAT + HAProxy monitor thread; timestomped to /usr/bin/ssh)"
  - "agetty (CurlRAT -> img.socialteams[.]store)"
  - "atd (CurlRAT; functions masqueraded as atd_ routines)"
  - "polkitd (CurlRAT)"
  - "sshd (SSH keylogger, plaintext credential capture)"
curlrat:
  - "six modes: 0 exec(popen), 1 config update, 2 staged download, 3 reverse shell + priv-esc, 4 sysinfo beacon, 5 PTY shell"
  - "victim ID: MD5(concat('cron_3.0pl1-137ubuntu3', hostname, ipv4, product_uuid)), uppercased"
c2_domains:
  - "img.monderhouse[.]space"
  - "img.smartnords[.]site"
  - "img.darklights[.]store"
  - "img.responsive.pstatic[.]autos"   # mimics Naver's CDN (pstatic)
  - "img.socialteams[.]store"
  - "img.worksongo[.]store"
file_paths:
  - "~/cache/haproxy-1000.cache (config); haproxy-1001/1002.cache (ACLs)"
  - "/var/lib/snapd/g580 (victim ID); /var/lib/snapd/ (CurlRAT staging)"
  - "/var/lib/sshd/c8c68e629bba773a10ac80012d10bf19 (SSH keylogger output)"
  - "/tmp/jasper-log (log sanitization)"
hashes_sha256:
  ted: ["72e70936f0dbe459142a1d867617c35f8d0cce5d18c6a49e1090a2a5adc8e558", "94630b96f628c96a6bff7904b40ffc9ad67c86f8a4ff6080c3b524831c93f402", "a8bfab4de81a1acb04aacdf757346946b0f5e30f0c9f402004016d0e425119c7"]
  stager: ["5db1b6d52faf60b4f32d6fd0c7c938e4d05d29a14c32ded4a9668357c08b6a91"]
  curlrat: ["83f7d565b0465546027052b597af46eae3a199e7a91fcc2ab936341147349130", "feeea9d0bf6ae7396d28271baa51ae50df5169ce5d32a516865856f91abc50b3", "4bb923eb040aa13ca8fd409c31ee4729c60ddff32e350efe1c5a4a9168a065f5"]
note: "Full IOC set is in Rapid7's report. Domains and IPs defanged."

No law-enforcement action or government advisory specific to this toolkit had been published as of this writing; the disclosure is vendor threat research by Rapid7 Labs.2 The remediation burden falls on defenders: because the backdoor is a recompiled build of a legitimate load balancer, the reliable detection is integrity verification against known-good HAProxy binaries and hunting for the specific artifacts (the magic path, the FIFO pipes, the trojanized daemons, the listed hashes and C2 domains), not signature-based scanning of a process that is, superficially, just HAProxy.2

Impact Assessment

  • Confirmed (per Rapid7): A backdoor compiled into victims' HAProxy 2.8.12 as a native plugin, capable of intercepting and injecting their SSL-decrypted web traffic and running C2 through the load balancer; a companion CurlRAT toolkit in five trojanized daemons; and an SSH keylogger capturing plaintext credentials.2
  • Confirmed: Targets are South Korean automotive and media organizations; earliest artifacts date to mid-2025, indicating long-dwell surveillance.2
  • Assessed: DPRK attribution at medium confidence (APT37- and Lazarus-overlapping); initial access via Groupware/mail-server CVE exploitation is Rapid7's working assumption, not confirmed.2
  • Unknown: The confirmed number of victim organizations; the exact initial-access vector; and whether APT37, Lazarus, or another DPRK unit is responsible.2

Lessons and Defensive Recommendations

For SOC and IR teams:

  • Add edge infrastructure — load balancers, reverse proxies, mail gateways — to your binary-integrity and detection scope. This backdoor is invisible to defenses that assume "HAProxy is HAProxy," because it is a recompiled build with a malicious plugin. Verify the integrity of load-balancer binaries against known-good hashes, and treat any locally-compiled or hash-mismatched build of a security appliance as suspect.
  • Hunt for the specific artifacts: the magic path /favorite_list_2x_m500_ico.jpg in web traffic, FIFO pipes matching /tmp/t*_w.pipe, trojanized daemons whose timestamps suspiciously match /usr/bin/ssh, the listed file paths and C2 domains, and log-sanitization staging files like /tmp/jasper-log. The counter-scrubbing means HAProxy's own stats cannot be trusted to reflect real connection volume on a compromised host.

For platform and infrastructure teams:

  • A load balancer terminates TLS, which means it sees everything in the clear — making it one of the highest-value places in a network to implant a passive collector. Restrict who can rebuild and deploy load-balancer binaries, sign and verify appliance builds, isolate the management plane, and monitor for unexpected plugins/filters loaded into HAProxy or similar proxies.
  • The assumed entry point is an internet-facing Groupware portal and mail server. Whether or not that is the vector here, edge web/mail applications remain a primary DPRK initial-access target for South Korean organizations; prioritise patching and exposure reduction on those systems.

For readers and defenders elsewhere:

  • The technique generalises beyond HAProxy and beyond South Korea: any software with a plugin or filter API that processes decrypted traffic is a candidate host for this kind of "hide inside trusted infrastructure" implant. The defensive posture — verify what your security-critical binaries actually are, don't just trust their name and location — is the transferable lesson.

Sources

Footnotes

  1. North Korea-linked Hackers Hide a Backdoor Inside HAProxy — Security Affairs, September 2026 ↩

  2. DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors — Rapid7 Labs, September 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20 ↩21 ↩22 ↩23 ↩24 ↩25 ↩26 ↩27 ↩28 ↩29 ↩30 ↩31 ↩32 ↩33 ↩34

  3. North Korean Hackers Deploy New Linux Espionage Toolkit — SecurityWeek, September 2026 ↩ ↩2

Topics: #ted-backdoor#curlrat#haproxy#dprk#apt37#lazarus#south-korea#rapid7#linux-implant
Original Incident Report →

Related Research

A North Korean-linked actor compromised Trading Technologies' X_TRADER, used it to breach 3CX, and shipped signed, trojanised VoIP clients to its customers — the first documented case of one software supply chain attack causing another.

Supply Chain AttackState-Sponsored

GTIG tracked UNC6240 (linked to ShinyHunters) mass-exploiting PeopleSoft's CVE-2026-35273 (CVSS 9.8 unauth RCE). Defenders who blocked /PSEMHUB at a WAF instead of patching were bypassed: the actor requested /%50SEMHUB/, one URL-encoded character, then dropped web shells and the SIDEEYE backdoor.

Data BreachMalwareExtortion & Blackmail

Bitget lost an initially-reported $351.6M — later revised to ~$387.5M — after attackers compromised a wallet-infrastructure backend, spoofed transaction data and pushed forged transfers through its own authorization workflow. Private-key theft was ruled out; Bitget suspects North Korea.

Cryptocurrency & Web3Financial Fraud