South Korean automotive and media organizations have been hit by a quiet Linux intrusion toolkit built for long-term access.
The malware hides inside software that manages web traffic, allowing attackers to watch users, steal information, and change pages delivered through compromised servers.
The operation appears designed for patience rather than disruption. Attackers likely entered through a groupware portal or mail server, used the edge server as a bridge into internal systems.
That pattern echoes the risks described in stealthy Linux server intrusions, where hidden access can remain active without drawing attention.
Analysts at Rapid7 identified the toolkit and assessed its link to DPRK-aligned advanced persistent threats with medium confidence.
Rapid7 said in a report shared with Cyber Security News (CSN) that the activity likely dates to early 2025, although the precise initial entry point and any exploited vulnerability have not been confirmed.
The affected organizations had ports 80, 443 and 25 exposed, with a groupware login service on port 443 and mail services on port 25.
These systems sit at the network edge, making their compromise serious: an intruder can collect credentials, move deeper inside, and potentially target visitors passing through that server.
DPRK-Linked Hackers Deploy Ted Backdoor
The central component, called ted backdoor, is a modified build of HAProxy 2.8.12, software commonly used to direct website traffic.
Instead of acting like a separate malicious program, it is compiled into the legitimate load balancer and uses its built-in features to inspect decrypted web requests while normal traffic continues to flow.
That placement gives the operators unusual control. The implant can capture session cookies and selected request details, run commands, upload or download files, and inject a malicious script into pages served to chosen visitors.
Its hidden command channel uses a request for a picture-like path, while its code also reduces HAProxy connection counters to make activity harder to spot. Researchers found an SSH keylogger as well as altered versions of crond, agetty, atd, sshd and polkitd.
The stager checks the operating system and whether HAProxy or cron is present before replacing the cron service, copying timestamps from a legitimate SSH binary, and removing chosen words from logs.
%20(Source%20-%20Rapid7).webp)
This reflects the same concern raised by Linux backdoors stealing SSH credentials: trusted system components can become the attacker’s hiding place.
CurlRAT supplies the remote-control layer. It polls attacker infrastructure for tasks, can execute commands, send system details, install added payloads, and open reverse or interactive shells with elevated privileges. A watchdog monitors HAProxy and reports whether the service starts, stops, reloads, or restarts.
Long-Term Espionage Risks and Defenses
Rapid7 said the combination of credential theft, web-session collection, selective page changes, and traffic redirection points to long-term espionage.
The targeting of South Korean media and automotive firms also fits a regional intelligence-gathering pattern. Readers following Kimsuky espionage activity in Korea will recognize why exposed groupware and stolen credentials remain valuable footholds.
The operators used basic XOR encryption and a substitution method to protect configurations and communications. Their command-and-control domains imitate image delivery services, including one that resembles a popular Korean web platform’s static-content naming style.
.webp)
Rapid7 also noted overlap in timing and delivery concepts with other DPRK activity, but said more evidence is needed for a firmer attribution. Defenders should review edge systems that handle web traffic, encryption, mail, or runtime modules.
They should compare deployed HAProxy and Linux service binaries against known versions, inspect unexpected shared libraries and cron changes, and rotate credentials that may have passed through affected servers. Independent network monitoring matters because logs on a compromised device may have been altered.
Teams should also investigate unusual requests to image-like paths, unexpected outbound connections from load balancers, and web responses that change only for particular visitors.
Regular patching of groupware and mail servers reduces likely entry opportunities. As shown by recent Asia-focused Linux espionage, post-compromise tools can turn a single exposed server into a durable route across an organization.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| SHA-256 | 5db1b6d52faf60b4f32d6fd0c7c938e4d05d29a14c32ded4a9668357c08b6a91 | CurlRAT stager |
| SHA-256 | 09739441ed4599bac2f8159028f772f71e4b25c8badfff95574e56d7384f3dbe | CurlRAT stager variant |
| SHA-256 | fea1bc36632c71e5a839803469ef60ac47595d36b2c50934ac109ade6df06e61 | CurlRAT stager variant |
| SHA-256 | 83f7d565b0465546027052b597af46eae3a199e7a91fcc2ab936341147349130 | CurlRAT |
| SHA-256 | 7007a78d50a993cb174c685eba96eb442c9507e38fd9d8e5dffc712f613ec110 | CurlRAT |
| SHA-256 | 6cf1b5e92a9c0756f597a5ddefb38eba32961c52efac7ab2a0aa52c639a8fc53 | CurlRAT |
| SHA-256 | ed72f4cd8d467b5c5d95ae6aeca4aaeea14d79565d379c1ca5871a714727be16 | CurlRAT |
| SHA-256 | feeea9d0bf6ae7396d28271baa51ae50df5169ce5d32a516865856f91abc50b3 | CurlRAT |
| SHA-256 | d53c760c23b4405eb04ad0f20ead375440344b3bdf1fb7854ed12e40d155eabe | Trojanized cronie binary |
| SHA-256 | 2f02b09d61d432134e994ad671258f523bbf289ae6091fd4eae192c60bd51b6f | Trojanized agetty binary |
| SHA-256 | 8f30b57928934ae67478d0e690c91d046e35a638da098d02922a4a88a0fdb66c | Trojanized atd binary |
| SHA-256 | a1d8af3a6acb731f07f72040eccb3450c1c83d40e29f736c2a63d35388660be4 | Trojanized polkitd binary |
| SHA-256 | 12810854c8b2c391b23e2e18b013e873d0369b0637aa3cf993136c07188ba3b8 | CurlRAT sample |
| SHA-256 | 009a1e2d7a582a24e50cf2ffc2a005482c8e38f22bf5ed416053855f8d054e1e | CurlRAT sample |
| SHA-256 | 4bb923eb040aa13ca8fd409c31ee4729c60ddff32e350efe1c5a4a9168a065f5 | SSH keylogger |
| SHA-256 | 94630b96f628c96a6bff7904b40ffc9ad67c86f8a4ff6080c3b524831c93f402 | Ted backdoor |
| SHA-256 | 72e70936f0dbe459142a1d867617c35f8d0cce5d18c6a49e1090a2a5adc8e558 | Modified HAProxy build containing ted backdoor |
| SHA-256 | a8bfab4de81a1acb04aacdf757346946b0f5e30f0c9f402004016d0e425119c7 | Ted backdoor sample |
| Domain | img.monderhouse.space | CurlRAT command-and-control infrastructure |
| Domain | img.smartnords.site | Command-and-control infrastructure |
| Domain | img.darklights.store | Backup CurlRAT configuration host |
| Domain | img.responsive.pstatic.autos | Command-and-control infrastructure masquerading as static content |
| Domain | img.socialteams.store | Command-and-control infrastructure |
| Domain | img.worksongo.store | Command-and-control infrastructure |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.

