Linux HAProxy backdoor toolkit targets South Korea

A newly uncovered Linux espionage toolkit is quietly turning HAProxy load balancers into surveillance platforms for long-term spying on South Korean automotive and media organizations, in a campaign attributed with medium confidence to North Korea–aligned operators by researchers at Rapid7 Labs.[1][2][6][13] The operation hinges on a trojanized HAProxy instance dubbed the ted backdoor, which is compiled directly into the open source proxy rather than exploiting a product flaw, allowing attackers to hijack web traffic and harvest credentials while blending into legitimate infrastructure.[1][2][5][12]

According to multiple technical analyses, the ted backdoor is delivered as a modified build of HAProxy 2.8.12 with custom code integrated into the balancer’s internal HTTP parsing logic.[1][5][6] From that vantage point, the implant can intercept and inspect HTTP requests and responses, selectively alter pages for specific visitors, inject malicious scripts into outbound traffic, and execute commands on the host under the guise of normal proxy activity.[2][5][6][13] Researchers note that the implant includes mechanisms to minimize or evade logging, helping the attackers maintain covert access to edge servers that sit directly in front of business-critical applications.[1][2][13]

The HAProxy backdoor is only one component of a broader Linux framework that Rapid7 describes as a previously undocumented espionage toolkit tailored for stealthy persistence.[1][6][13] The campaign also makes use of a curl-based remote access tool known as CurlRAT, which is implanted into trojanized versions of common system daemons including crond, agetty, atd, sshd, and polkitd, effectively turning routine background processes into command-and-control beacons.[1][5][6][13] Additional components identified in reporting include an SSH keylogger and a stager, giving the operators the ability to capture authentication material and deploy further payloads once they have footholds on exposed Linux servers.[5][6] Evidence suggests the toolkit has likely been in use since at least late 2024 or early 2025, with confirmed compromises at two South Korean organizations.[1][5][6][13]

Rapid7 assesses that the activity is linked to DPRK state-sponsored actors, citing infrastructure and tradecraft overlaps with known North Korean clusters such as APT37, Lazarus, and Kimsuky, while stressing that the responsible group cannot yet be pinned down more precisely.[5][6][10][13] Other recent investigations into North Korean operations against South Korean organizations have documented related families of Linux backdoors, including Gomir, BirdTroy, and DriveTroy, used in campaigns against groupware vendors and enterprise collaboration platforms.[8][9][14][15] Some industry analysis has speculated that the HAProxy toolkit operators are gaining initial access by exploiting vulnerabilities in public-facing web applications and groupware portals, but Rapid7’s write-up notes that both the intrusion vector and any specific exploited CVEs remain unconfirmed in this case.[6][10]

Crucially for defenders, there is no indication that the ted backdoor campaign leverages a native vulnerability in HAProxy itself, and researchers explicitly state that the malware is a trojanized build requiring prior code execution on the target server.[2][5][12] As a result, the activity is not currently tied to any NVD-listed HAProxy CVE, nor is there a corresponding CVSS score; the risk stems from post-compromise modification of widely deployed proxy binaries rather than an upstream flaw in the software.[2][5][6] That distinction means organizations cannot rely on traditional patch-and-forget workflows and must instead focus on detecting unauthorized changes to HAProxy installations and the Linux services surrounding them.[5][6][13]

For organizations running HAProxy at the edge, particularly in South Korea’s automotive and media sectors, the findings underscore the need to treat load balancers as high-value assets and verify their integrity as carefully as web applications.[1][5][13] Security teams should compare deployed HAProxy binaries against trusted distributions, monitor for unexpected behavior in system daemons such as crond and sshd, and hunt for anomalous curl activity consistent with CurlRAT-style remote access tooling, using indicators and YARA rules released by research teams where available.[5][6][10][13] Hardened access controls around internet-facing groupware and portal applications, rapid patching of known vulnerabilities in those stacks, and targeted monitoring for North Korean APT techniques can help reduce the likelihood that attackers gain the level of host access required to implant a backdoored HAProxy in the first place.[6][10][13]

References

  1. North Korean Hackers Deploy New Linux Espionage Toolkit
  2. New Ted Backdoor Hides Inside Victims’ Own HAProxy …
  3. Ted Backdoor: Trojanized HAProxy Hits South Korea – CyberWorldOps
  4. DPRK-Linked Actors Deploy HAProxy Backdoor and CurlRAT …
  5. Springtail: New Linux Backdoor Added to Toolkit
  6. 신종 Gomir Family를 이용한 Kimsuky의 국내 그룹웨어 …
  7. DPRK APTs: Ted backdoor and curlRAT target South …
  8. Posts of last 24 hours | Security Aggregator
  9. IntelFreed.com | Cybersecurity Intelligence Weather Report
  10. North Korea Hid New Google Drive Backdoors Inside South Korean Groupware Firms
  11. Kimsuky Hit South Korean Groupware Vendor With New …

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply