www.rapid7.com
New Ted Backdoor Targets South Korean Media and Automotive Sectors
Article Content
A new Linux toolkit, named the 'ted backdoor', has been discovered targeting South Korean organizations in the media and automotive sectors. This toolkit, attributed to North Korean state actors, integrates into HAProxy load balancers to intercept web traffic and deliver altered content. The toolkit allows attackers to execute remote commands, perform credential harvesting, and engage in long-term surveillance. Evidence suggests that the attacks may have been ongoing since early 2025, with the toolkit utilizing trojanized versions of various system binaries. The attack vector likely involves exploiting exposed Groupware portals, consistent with previously documented tactics used by the Kimsuky group. Rapid7 Labs has noted that the command-and-control requests are hidden from backend logs, complicating detection efforts. Further evidence is needed to establish a definitive timeline and initial access method. The toolkit's stealthy nature and integration with existing systems pose significant risks to affected organizations.
Key Points: • The 'ted backdoor' toolkit targets South Korean media and automotive sectors. • It integrates into HAProxy to intercept and alter web traffic without detection. • Attribution to North Korean state actors suggests a long-term espionage campaign.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.