Rapid7 Labs identified a previously undocumented Linux espionage toolkit used against South Korean automotive and media organizations from at least early 2025. The toolkit includes a trojanized HAProxy 2.8.12 build, dubbed ted backdoor, CurlRAT implanted in legitimate Linux daemons, a stager, and an SSH keylogger. Ted backdoor is integrated into HAProxy internals to intercept HTTP traffic, collect session material, inject scripts into selected web responses, execute commands, and suppress or evade logging.
Rapid7 attributed the activity to DPRK-linked operators with medium confidence, citing infrastructure associations with APT37, while noting that the responsible cluster, initial-access method, and any exploited vulnerability remain unconfirmed. The operation follows broader DPRK activity against South Korean organizations, including Lazarus’s 2024–2025 SyncHole watering-hole campaign exploiting locally prevalent security and file-transfer software. Defenders should validate the integrity of HAProxy and Linux daemon binaries, hunt associated filesystem and C2 artifacts, and use independent network telemetry because compromised service logs may be unreliable.

TTPs, infrastructure, and targeting history in one profile.
8 events from the most recent confirmed update back to the earliest known activity.
The earliest identified VirusTotal uploads associated with the Linux espionage toolkit date to mid-2025.
A likely long-term espionage campaign targeted South Korean automotive and media organizations using a trojanized HAProxy build dubbed ted backdoor, CurlRAT-modified Linux daemons, a stager, and an SSH keylogger. Rapid7 assessed the activity as DPRK-linked with medium confidence, citing South Korean targeting and infrastructure associations with APT37, while the initial-access vector remained unconfirmed.
The first known SyncHole infection was discovered at a South Korean software company, where a ThreatNeedle backdoor ran in memory within the legitimate Cross EX child process SyncHost.exe. The Lazarus campaign subsequently targeted at least six organizations across South Korea using watering-hole redirection and likely Cross EX vulnerability exploitation.
Mandiant responded to additional DPRK-nexus software supply-chain attacks tracked as UNC4899, which it assessed were likely conducted by the actor publicly known as TraderTraitor.
Public reporting described the exposure of a suspected APT37 GitHub repository containing malware samples, files, tooling, and decoy documents.
Mandiant responded to DPRK-linked operations tracked as UNC4736, which overlapped with public AppleJeus reporting. The actor compromised 3CX and Trading Technologies through software supply-chain attacks to steal credentials and access multiple networks.
Open-source reporting alleged that APT37 distributed a compressed file masquerading as a password file; the reported payload was LOGCABIN, which Mandiant attributes to APT43.
A GitHub repository reportedly linked to an APT37 member was used as staging infrastructure from at least 2021; it contained samples, tooling, and decoy documents themed around South Korean education, government, and finance targets.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 52 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
7 references tracked. Mallory keeps watching after this page renders.
infosec.pub
Open sourcebsky.app
Open sourcescworld.com
Open sourcethehackernews.com
Open sourcerapid7.com
Open sourcesecurelist.com
Open sourcecloud.google.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.