ThreatPaper
Assessed, Not Confirmed

The ted/CurlRAT HAProxy toolkit is North Korean

Assessment

Coverage frames the ted backdoor and CurlRAT toolkit as North Korean. Rapid7's own attribution is medium confidence: the command-and-control infrastructure is associated with APT37 by ThreatFox and maltrail, and the tradecraft overlaps documented APT37 (Operation Code on Toast) and Lazarus (Operation SyncHole) activity against South Korean organizations. But Rapid7 explicitly states that 'further evidence is necessary to make a more definitive assessment,' and does not resolve whether APT37, Lazarus, or another DPRK unit is responsible — APT37 and Lazarus sit under different DPRK agencies and both run parallel espionage against South Korea. So the DPRK direction of travel is well-supported, but a headline that presents a single confirmed North Korean group is more certain than the evidence, which places responsibility on a cluster whose exact identity is still open.

Where this claim appeared

Rapid7 · 2026-09-30

https://www.rapid7.com/blog/post/tr-dprk-apts-ted-backdoor-curlrat-target-south-korean-media-automotive-sectors/

What “Assessed, Not Confirmed” means

A named source states this as its own assessment, at its own stated confidence, rather than as established fact. Attribution to a nation state usually sits here. The assessment is real and reportable; treating it as settled is the error.

4 of 5 · rating scale

Assessed in

ted backdoor: North Korea hides a Linux implant inside victims' HAProxy load balancers

Think this assessment is wrong? Report an error.