New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic
AI Summary
A previously undocumented Linux backdoor named 'ted' has been discovered embedded within trojanized HAProxy binaries deployed at two South Korean organizations in the automotive and media sectors. The implant intercepts web traffic, enables command-and-control (C2) communication by mimicking legitimate HTTP responses, and allows attackers to execute shell commands, upload/download files, and modify configurations. Rapid7 Labs attributes the activity with medium confidence to North Korean state-sponsored actors, potentially linked to APT37, Lazarus, and Kimsuky clusters, based on infrastructure overlaps and operational patterns. The backdoor evades logging by manipulating HAProxy's internal connection counters and uses trojanized system binaries such as crond, sshd, agetty, atd, and polkitd to maintain persistence and exfiltrate credentials.
AI-extracted · verify before operational use
Extracted Entities 2 found
Indicators of Compromise 12 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | img[.]monderhouse[.]space | Details → |
| Domain | img[.]smartnords[.]site | Details → |
| Domain | img[.]darklights[.]store | Details → |
| Domain | img[.]responsive[.]pstatic[.]autos | Details → |
| Domain | img[.]socialteams[.]store | Details → |
| Domain | img[.]worksongo[.]store | Details → |
| Filename | ~/cache/haproxy-1000.cache | Details → |
| Filename | /var/lib/sshd/c8c68e629bba773a10ac80012d10bf19 | Details → |
| Filename | /var/lib/snapd/g580 | Details → |
| Filename | /tmp/jasper-log | Details → |
| SHA-256 | 72e70936f0dbe459142a1d867617c35f8d0cce5d18c6a49e1090a2a5adc8e558 | Details → |
| SHA-256 | 4bb923eb040aa13ca8fd409c31ee4729c60ddff32e350efe1c5a4a9168a065f5 | Details → |