ThreatPaper
Weak Evidence

Initial access came via Groupware portal CVE exploitation

Assessment

Reporting describes the intrusions as beginning with exploitation of the victims' internet-facing Groupware portal. This is Rapid7's working assumption, not a confirmed finding: Rapid7's analysis states the scenario 'assumes the initial access is obtained by exploitation of CVEs related to the Groupware portal.' The circumstantial basis is real — both victims exposed a Groupware login on port 443 and a mail server on port 25, an exposure pattern consistent with documented DPRK/Kimsuky tradecraft against South Korean groupware vendors — but Rapid7 did not observe the entry point directly, and no specific CVE is tied to these intrusions. Readers should treat 'they got in through the Groupware portal' as a plausible reconstruction rather than an established fact; the confirmed part of the story starts at the recompiled HAProxy build, not before it.

Where this claim appeared

Rapid7 · 2026-09-30

https://www.rapid7.com/blog/post/tr-dprk-apts-ted-backdoor-curlrat-target-south-korean-media-automotive-sectors/

What “Weak Evidence” means

Evidence exists but is thin, circumstantial, or explicitly qualified as weak by the source that published it. Shared hosting infrastructure between threat clusters is the recurring example.

3 of 5 · rating scale

Assessed in

ted backdoor: North Korea hides a Linux implant inside victims' HAProxy load balancers

Think this assessment is wrong? Report an error.