Back to feed

Rapid7 finds North Korean Linux toolkit in trojanized HAProxy at South Korean firms

2 min
Rapid7 finds North Korean Linux toolkit in trojanized HAProxy at South Korean firms

This digest was compiled by AI from multiple sources — links to the originals are below.

Rapid7 Labs discovered a Linux toolkit, dubbed 'ted', embedded in trojanized HAProxy load balancers at two South Korean organizations. The implant, attributed with medium confidence to North Korean state-sponsored actors, targets automotive and media sectors. Attackers replaced the legitimate HAProxy binary to intercept traffic and serve modified content to selected visitors.

Key Facts

  • The toolkit, named 'ted' by its creators, was found in trojanized HAProxy load balancers at two South Korean organizations.
  • Rapid7 Labs attributes the implant to North Korean state-sponsored actors with medium confidence.
  • The implant targets entities in South Korea's automotive and media sectors.
  • Attackers replaced the legitimate HAProxy binary after executing code on the host, rather than exploiting a vulnerability.
  • The toolkit includes a trojanized SSH daemon for password capture and a remote access trojan named curlRAT.

Implant Discovery

Rapid7 Labs identified the toolkit, dubbed 'ted', embedded within trojanized HAProxy load balancers at two South Korean organizations. The implant is attributed to North Korean state-sponsored actors with medium confidence. Targets include entities in South Korea's automotive and media sectors. The attackers gained access by executing code on the host and replacing the legitimate HAProxy binary, rather than exploiting a vulnerability.

Traffic Interception and Evasion

The toolkit intercepts web traffic and selectively serves modified content to specific visitors. It filters requests based on User-Agent, URL, referrer patterns, and client IP addresses. The implant manipulates HTTP headers to conceal modifications. Command-and-control requests are erased from HAProxy's connection counters, leaving no trace in backend logs or load balancer statistics.

Initial Access and Additional Tools

Evidence suggests the attackers may have gained initial access through an exposed Groupware portal, a common Korean enterprise collaboration software. The toolkit includes a trojanized SSH daemon for capturing passwords. A companion remote access trojan named curlRAT is also part of the toolkit. Rapid7 recommends network correlation, memory behavioral analysis, and binary integrity checks for detection.

2 sources

Time · lag behind first