Rapid7: Ted HAProxy backdoor and curlRAT hit South Korean media and automotive (medium-confidence DPRK)
Rapid7 Labs (4 September 2026) describes a Linux toolkit that compiles the Ted implant into victims' own HAProxy 2.8.x builds so it can intercept selected web traffic, hide C2 from HAProxy stats, rewrite responses, and run commands via a named pipe under /tmp. It is not an HAProxy CVE: operators need code execution on the host and the ability to replace binaries. Companion tooling includes a trojanized sshd password logger, a stager that overwrites crond (CentOS 7.7-7.9 / Ubuntu 22.04 paths cited), and curlRAT (distinct from SideCopy's CurlBack). Rapid7 attributes the activity with medium confidence to DPRK APTs (ThreatFox/maltrail links to APT37 C2 lists) against South Korean automotive and media victims; initial access is hypothesised via exposed Groupware/mail edges consistent with Kimsuky tradecraft, not proven. Hunt for unexpected HAProxy rebuilds, crond/sshd replacements, and the IoCs in Rapid7's post; do not expose Groupware portals without patching and MFA.
- Product
- HAProxy (trojanized builds); related Linux binaries (sshd/crond/curlRAT)
- Versions
- Observed with HAProxy 2.8.12-class builds; not a vendor HAProxy vulnerability
- Exploited in Australia?
- unknown
- Patch to
- Rebuild/replace HAProxy from trusted sources; verify sshd/crond integrity; hunt Rapid7 IoCs; harden Groupware/mail edges
Primary: Rapid7 Labs (4 Sep 2026) ยท Vendor: The Hacker News (4 Sep 2026)
