#rapid7
2 cases
Rapid7's October 2, 2026 report details AVERAT and new BPFDoor/Rekoobe Linux implants that hide C2 in SMTP port 25 to mimic South Korean (SpamSniper) and Taiwanese (ShareTech) mail-security appliances and relay through compromised NAS, DVR and SMB devices against telecom targets.
Malware
ted backdoor: North Korea hides a Linux implant inside victims' HAProxy load balancersState-SponsoredMalware
Rapid7 found 'ted', a backdoor a DPRK-linked APT compiled into victims' HAProxy load balancers as a native plugin — reading their decrypted traffic and routing C2 through the load balancer itself. A companion CurlRAT toolkit hid in five trojanized Linux daemons; targets were South Korean firms.
State-SponsoredMalware