DPRK APTs: Ted Backdoor and curlRAT Target South Korean Media and Automotive Sectors
Rapid7, Friday, September 4th, 2026
Rapid7 Labs documents a stealthy Linux toolkit used by DPRK-linked actors against South Korean automotive and media firms.
Rapid7 Labs identified a previously undocumented Linux toolkit that has been targeting South Korean automotive and media organizations with very little detection.
The campaign centered on a HAProxy instance named the "ted backdoor", used alongside trojanized versions of crond, agetty, atd, sshd and polkitd.
The framework let operators execute remote commands, inject malicious scripts into web traffic, harvest credentials and conduct long-term surveillance. Its defining feature is depth of integration with the victim environment: the ted backdoor is compiled as part of the target's existing HAProxy build rather than dropped as a separate binary.