1. Basic Information
Article Title: DPRK APTs deploy ted backdoor and curlRAT against South Korean sectors
Source: Rapid7
Publication Date: 2026-09-04
Original URL: Rapid7
1. Basic Information Article Title: DPRK APTs deploy ted backdoor and curlRAT against...
1. Basic Information
Article Title: DPRK APTs deploy ted backdoor and curlRAT against South Korean sectors
Source: Rapid7
Publication Date: 2026-09-04
Original URL: Rapid7

Ted hides inside trojanized HAProxy builds to intercept traffic and serve altered pages at two South Korean organizations.

North Korean hackers have been using a new Linux toolkit for long-term surveillance against automotive and media sectors.

Kimsuky used fake security tools and Webex pages in March-April 2026 to deploy HTTPSpy, enabling persistent espionage and data…

North Korean hackers are targeting open source software developers with a backdoor and an information stealer as part of a broad…

Unit 42 links CL-STA-1062 to TinyRCT, a custom .NET backdoor used against government and energy targets in Southeast Asia.

Proofpoint says UNK_DeadDrop sent 250+ phishing emails to nearly 100 firms, using GitHub and VS Code lures to steal credentials…