Threat Advisory

Ted Backdoor and CurlRAT Facilitate Account Theft and Details Leakage by Network Alteration

Threat: Malware
Targeted Region: South Korea
Targeted Sector: Technology & IT, Entertainment & Telecommunication
Criticality: High
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

A Linux-based malware toolkit has been observed targeting organizations in South Korea's media and automotive sectors as part of activity assessed with medium confidence as being linked to DPRK-aligned threat actors. The toolkit includes the previously undocumented Ted backdoor, curlRAT, a credential-stealing SSH keylogger, and a stager designed to compromise legitimate Linux services. The activity appears focused on maintaining long-term access, conducting surveillance, harvesting credentials, executing commands, and manipulating web traffic while minimizing detection.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

A Linux-based malware toolkit has been observed targeting organizations in South Korea's media and automotive sectors as part of activity assessed with medium confidence as being linked to DPRK-aligned threat actors. The toolkit includes the previously undocumented Ted backdoor, curlRAT, a credential-stealing SSH keylogger, and a stager designed to compromise legitimate Linux services. The activity appears focused on maintaining long-term access, conducting surveillance, harvesting credentials, executing commands, and manipulating web traffic while minimizing detection.[emaillocker id="1283"]

The attack chain appears to begin with compromise of an externally exposed Groupware or mail service, followed by persistence on an edge server and credential harvesting through an SSH keylogger. A stager profiles the compromised Linux host and selectively deploys trojanized versions of services such as crond, agetty, atd, polkitd, and HAProxy. curlRAT provides command execution, reverse-shell and interactive PTY capabilities, system reconnaissance, payload downloading, configuration updates, and C2 communication over HTTP/HTTPS using Base64 and XOR-based encryption. The Ted backdoor is particularly stealthy because it is compiled directly into HAProxy and hooks its HTTP-processing functionality to intercept traffic, capture selected HTTP headers and session information, execute attacker commands, transfer files, update configurations, and inject malicious scripts into webpages viewed by targeted users. It can also manipulate HAProxy connection statistics and terminate malicious C2 requests at the load balancer so that backend systems do not record the traffic.

The campaign represents a stealth-focused Linux intrusion framework capable of combining credential theft, persistent backdoor access, internal reconnaissance, command execution, traffic interception, and data theft within compromised infrastructure. Its integration into legitimate system services makes conventional file-based detection more difficult and allows malicious activity to blend with normal server operations. Organizations operating Linux-based edge servers, HAProxy infrastructure, groupware portals, and internet-facing services should monitor for unexpected modifications to system binaries, anomalous HAProxy behavior, unauthorized configuration files, suspicious outbound connections, credential harvesting activity, and unexplained changes to system logs.

 

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1190 Exploit Public Facing Application-
Initial access T1195 Supply Chain Compromise -
Execution T1204.002 User Execution Malicious File
Persistence T1543.003 Create or Modify System Process Windows Service
Defence Evasion T1036.005 Masquerading Match Legitimate Resource Name or Location
Credential access T1555.003 Credentials from Password Stores Credentials from Web Browsers
Collection T1005 Data from Local System -
Collection T1560.001 Archive Collected Data Archive via Utility
Command and control T1071.001 Application Layer Protocol Web Protocols
Exfiltration T1041 Exfiltration Over C2 Channel -

 

MBC PROFILE:

Objective Behavior ID Behavior
Command & Control B0030 C2 Communication
Impact B0022 Remote Access
Exfiltration E1020 Automated Exfiltration
Cryptography Micro-objective C0031 Decrypt Data
Discovery E1083 File and Directory Discovery
Anti-Static Analysis B0032 Executable Code Obfuscation
Anti-Static Analysis E1027 Obfuscated Files or Information
Execution E1204 User Execution
Persistence F0012 Registry Run Keys / Startup Folder

 

REFERENCES:

The following reports contain further technical details:
https://www.rapid7.com/blog/post/tr-dprk-apts-ted-backdoor-curlrat-target-south-korean-media-automotive-sectors/

[/emaillocker]
crossmenu