New 'ted' backdoor hidden in trojanized HAProxy
🛡️ A previously undocumented Linux toolkit named ted was compiled into trojanized HAProxy binaries on two South Korean hosts, intercepting web traffic and serving altered pages to selected visitors. Rapid7 links the implant with medium confidence to North Korean state actors and identifies victims in the automotive and media sectors. The implant uses specially crafted requests to enter C2 mode, erases its activity from HAProxy counters and returns operator responses over ordinary HTTP headers. Rapid7 shared IoCs and recommended network correlation, memory analysis and binary integrity checks.
