North Korea-aligned threat actors have been using a new Linux toolkit in attacks targeting automotive and media organizations in South Korea, Rapid7 reports.
Designed for long-term surveillance, the framework consists of a HAProxy instance called ‘ted backdoor’ and trojanized versions of tools such as ‘agetty’, ‘atd’, ‘crond’, ‘polkitd’, and ‘sshd’.
The toolkit supports remote command execution, credential harvesting, and script injection into web traffic, enabling attackers to spy on victims for long periods of time without detection.
According to Rapid7, the framework is deeply integrated within the target infrastructure, with the ted backdoor being compiled as part of the HAProxy version 2.8.12 running on the victim’s environment.
“It uses its native filter API, internal memory pools, event scheduler, and process management infrastructure to intercept traffic and hide from monitoring, while genuine load balancing traffic operates as expected,” the cybersecurity firm explains.








