New Ted Backdoor Targets South Korean Media and Automotive Sectors

New Ted Backdoor Targets South Korean Media and Automotive Sectors

First seen 4 Sep 2026, 15:46 UTC Thehackernewswww.rapid7.com 68.0

Article Content

Browse articles
ThreatCluster

A new Linux toolkit, named the 'ted backdoor', has been discovered targeting South Korean organizations in the media and automotive sectors. This toolkit, attributed to North Korean state actors, integrates into HAProxy load balancers to intercept web traffic and deliver altered content. The toolkit allows attackers to execute remote commands, perform credential harvesting, and engage in long-term surveillance. Evidence suggests that the attacks may have been ongoing since early 2025, with the toolkit utilizing trojanized versions of various system binaries. The attack vector likely involves exploiting exposed Groupware portals, consistent with previously documented tactics used by the Kimsuky group. Rapid7 Labs has noted that the command-and-control requests are hidden from backend logs, complicating detection efforts. Further evidence is needed to establish a definitive timeline and initial access method. The toolkit's stealthy nature and integration with existing systems pose significant risks to affected organizations.

Key Points: • The 'ted backdoor' toolkit targets South Korean media and automotive sectors. • It integrates into HAProxy to intercept and alter web traffic without detection. • Attribution to North Korean state actors suggests a long-term espionage campaign.

Ask AI about this cluster

Timeline

2025-01-01
Initial deployment of ted backdoor suspected
Rapid7 suggests that the toolkit may have been used in attacks since early 2025, targeting South Korean organizations.
Rapid7
2026-09-04
Rapid7 publishes findings
Rapid7 Labs releases a report detailing the capabilities and targets of the ted backdoor toolkit.
Rapid7
2026-09-04
The Hacker News reports on ted backdoor
The Hacker News covers the same findings, emphasizing the stealthy nature of the toolkit and its command-and-control methods.
The Hacker News