Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Kimsuky Hackers Leverage AI to Automate Phishing LNK Attacks
September 7, 2026
North Korean Hackers Attack South Korea with Ted Backdoor and CurlRAT
September 7, 2026
Roundcube Patches Critical Zero-Click XSS, SSRF Bypass Flaws
September 7, 2026
Home/Threats/North Korean Hackers Attack South Korea with Ted Backdoor and CurlRAT
Threats

North Korean Hackers Attack South Korea with Ted Backdoor and CurlRAT

Key Takeaways North Korean state-sponsored hackers have infiltrated South Korean media and automotive sectors. The attackers utilized a sophisticated Linux toolkit, including the “ted...

Sarah simpson
Sarah simpson
September 7, 2026 4 Min Read
4 0

Key Takeaways

  • North Korean state-sponsored hackers have infiltrated South Korean media and automotive sectors.
  • The attackers utilized a sophisticated Linux toolkit, including the “ted backdoor” and “CurlRAT,” designed for stealthy, long-term espionage.
  • The primary entry points appear to be internet-facing groupware portals and mail servers.
  • The malware operates by modifying legitimate software like HAProxy, making detection difficult.
  • Organizations should audit edge systems, compare binaries, and rotate credentials to mitigate risks.

South Korean organizations operating within the automotive and media industries have fallen victim to a stealthy Linux intrusion campaign. This sophisticated operation deploys a custom toolkit engineered for persistent access and covert data exfiltration.

Table Of Content

  • Key Takeaways
  • DPRK-Linked Hackers Deploy Ted Backdoor
  • Long-Term Espionage Risks and Defenses
  • What You Should Do

The malicious software is ingeniously embedded within legitimate web traffic management applications. This strategic placement allows the attackers to monitor user activity, pilfer sensitive information, and even manipulate content served through compromised servers without immediate detection.

Analysts suggest the campaign prioritizes enduring presence over rapid disruption. Initial access likely occurred via internet-exposed groupware portals or mail servers. The compromised edge servers then served as conduits for deeper penetration into internal networks. This attack methodology aligns with known patterns of stealthy Linux server intrusions, where illicit access can persist for extended periods unnoticed.

Security researchers at Rapid7 said in a report that they identified this toolkit and, with medium confidence, linked the activity to advanced persistent threat (APT) groups associated with North Korea. The report, shared with Cyber Security News (CSN), indicates that the attacks likely commenced in early 2025. While the precise initial access vector and any specific vulnerabilities exploited remain unconfirmed, the targeted organizations typically had ports 80, 443, and 25 exposed, hosting groupware login services and mail services.

The compromise of these network edge systems is critical. Such access enables attackers to harvest credentials, move laterally within the network, and potentially target unsuspecting visitors whose traffic passes through the affected servers.

DPRK-Linked Hackers Deploy Ted Backdoor

At the core of this operation is a component dubbed “ted backdoor,” a specially modified version of HAProxy 2.8.12, a widely used software for directing web traffic. Rather than functioning as a standalone malicious executable, the backdoor is compiled directly into the legitimate load balancer. It leverages HAProxy’s inherent capabilities to scrutinize decrypted web requests while normal traffic continues unimpeded.

This deep integration grants the attackers extensive control. The implant can capture session cookies and specific request details, execute arbitrary commands, facilitate file uploads and downloads, and inject malicious scripts into web pages delivered to targeted users. Its clandestine command-and-control channel utilizes requests for image-like file paths, while its code also manipulates HAProxy connection counters to obscure its activities further. Researchers also uncovered an SSH keylogger and tampered versions of critical system binaries such as crond, agetty, atd, sshd, and polkitd.

The initial stager in the attack chain first assesses the operating system and checks for the presence of HAProxy or cron. It then replaces the legitimate cron service, copies timestamps from a genuine SSH binary to evade detection, and meticulously removes specific keywords from system logs. This tactic underscores a recurring concern with Linux backdoors that steal SSH credentials: trusted system components can be repurposed as stealthy hiding places for attackers.

Complementing the ted backdoor is CurlRAT, which provides the remote-control capabilities. CurlRAT periodically communicates with attacker infrastructure to retrieve tasks. It can execute commands, transmit detailed system information, deploy additional payloads, and establish reverse or interactive shells with elevated privileges. A built-in watchdog mechanism monitors HAProxy, reporting on its status, including starts, stops, reloads, or restarts.

Long-Term Espionage Risks and Defenses

Rapid7 concluded that the combination of credential theft, web session hijacking, selective page modification, and traffic redirection strongly points to a campaign focused on long-term espionage. The specific targeting of South Korean media and automotive companies aligns with established regional intelligence-gathering objectives. Organizations familiar with Kimsuky espionage activities in Korea will recognize the strategic value of compromised groupware and stolen credentials as persistent footholds.

The attackers employed basic XOR encryption and a substitution cipher to safeguard their configurations and communications. Their command-and-control domains are designed to mimic legitimate image delivery services, with one domain specifically adopting the static-content naming conventions of a popular Korean web platform.

While Rapid7 observed similarities in timing and delivery techniques with other DPRK-linked activities, they emphasized the need for more conclusive evidence for a definitive attribution. Defenders must meticulously examine edge systems responsible for web traffic, encryption, mail services, or runtime modules.

What You Should Do

  • Audit Edge Systems: Regularly review and audit all internet-facing systems, especially those handling web traffic (ports 80, 443), mail services (port 25), and groupware portals.
  • Verify Binaries: Compare deployed HAProxy and other critical Linux service binaries against known, untampered versions. Implement file integrity monitoring (FIM) to detect unauthorized modifications.
  • Inspect Shared Libraries and Cron Jobs: Look for unexpected shared libraries and unauthorized changes to cron configurations, as these are common hiding places for persistence.
  • Rotate Credentials: Immediately rotate all credentials that may have passed through or been stored on affected servers.
  • Implement Independent Network Monitoring: Deploy network monitoring solutions that operate independently of potentially compromised hosts. This helps detect anomalous outbound connections from load balancers or unusual requests to image-like paths, even if local logs are tampered with.
  • Analyze Web Responses: Investigate web responses that exhibit selective changes for specific visitors, as this could indicate content injection.
  • Patch Regularly: Ensure all groupware and mail servers are consistently patched and updated to mitigate known vulnerabilities that could serve as initial entry points.
  • Review IoCs: Utilize the provided Indicators of Compromise (IoCs) within your threat intelligence platforms (e.g., MISP, VirusTotal, SIEM) to scan for and block known malicious files and domains.
    Type Indicator Description
    SHA-256 5db1b6d52faf60b4f32d6fd0c7c938e4d05d29a14c32ded4a9668357c08b6a91 CurlRAT stager
    SHA-256 09739441ed4599bac2f8159028f772f71e4b25c8badfff95574e56d7384f3dbe CurlRAT stager variant
    SHA-256 fea1bc36632c71e5a839803469ef60ac47595d36b2c50934ac109ade6df06e61 CurlRAT stager variant
    SHA-256 83f7d565b0465546027052b597af46eae3a199e7a91fcc2ab936341147349130 CurlRAT
    SHA-256 7007a78d50a993cb174c685eba96eb442c9507e38fd9d8e5dffc712f613ec110 CurlRAT
    SHA-256 6cf1b5e92a9c0756f597a5ddefb38eba32961c52efac7ab2a0aa52c639a8fc53 CurlRAT
    SHA-256 ed72f4cd8d467b5c5d95ae6aeca4aaeea14d79565d379c1ca5871a714727be16 CurlRAT
    SHA-256 feeea9d0bf6ae7396d28271baa51ae50df5169ce5d32a516865856f91abc50b3 CurlRAT
    SHA-256 d53c760c23b4405eb04ad0f20ead375440344b3bdf1fb7854ed12e40d155eabe Trojanized cronie binary
    SHA-256 2f02b09d61d432134e994ad671258f523bbf289ae6091fd4eae192c60bd51b6f Trojanized agetty binary
    SHA-256 8f30b57928934ae67478d0e690c91d046e35a638da098d02922a4a88a0fdb66c Trojanized atd binary
    SHA-256 a1d8af3a6acb731f07f72040eccb3450c1c83d40e29f736c2a63d35388660be4 Trojanized polkitd binary
    SHA-256 12810854c8b2c391b23e2e18b013e873d0369b0637aa3cf993136c07188ba3b8 CurlRAT sample
    SHA-256 009a1e2d7a582a24e50cf2ffc2a005482c8e38f22bf5ed416053855f8d054e1e CurlRAT sample
    SHA-256 4bb923eb040aa13ca8fd409c31ee4729c60ddff32e350efe1c5a4a9168a065f5 SSH keylogger
    SHA-256 94630b96f628c96a6bff7904b40ffc9ad67c86f8a4ff6080c3b524831c93f402 Ted backdoor
    SHA-256 72e70936f0dbe459142a1d867617c35f8d0cce5d18c6a49e1090a2a5adc8e558 Modified HAProxy build containing ted backdoor
    SHA-256 a8bfab4de81a1acb04aacdf757346946b0f5e30f0c9f402004016d0e425119c7 Ted backdoor sample
    Domain img.monderhouse.space CurlRAT command-and-control infrastructure
    Domain img.smartnords.site Command-and-control infrastructure
    Domain img.darklights.store Backup CurlRAT configuration host
    Domain img.responsive.pstatic.autos Command-and-control infrastructure masquerading as static content
    Domain img.socialteams.store Command-and-control infrastructure
    Domain img.worksongo.store Command-and-control infrastructure

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitHackerMalwarePatchSecurityThreatVulnerability

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Roundcube Patches Critical Zero-Click XSS, SSRF Bypass Flaws

Next Post

Kimsuky Hackers Leverage AI to Automate Phishing LNK Attacks

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
OpenVPN Patches 7 High-Severity Flaws Exposing VPN Connections
September 7, 2026
N-able Patches Critical RCE Vulnerability in N-central Platform
September 7, 2026
New Chrome Extension Steals Login Sessions, Creates Backdoors
September 7, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us