EXECUTIVE SUMMARY:
A Linux-based malware toolkit has been observed targeting organizations in South Korea's media and automotive sectors as part of activity assessed with medium confidence as being linked to DPRK-aligned threat actors. The toolkit includes the previously undocumented Ted backdoor, curlRAT, a credential-stealing SSH keylogger, and a stager designed to compromise legitimate Linux services. The activity appears focused on maintaining long-term access, conducting surveillance, harvesting credentials, executing commands, and manipulating web traffic while minimizing detection.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
A Linux-based malware toolkit has been observed targeting organizations in South Korea's media and automotive sectors as part of activity assessed with medium confidence as being linked to DPRK-aligned threat actors. The toolkit includes the previously undocumented Ted backdoor, curlRAT, a credential-stealing SSH keylogger, and a stager designed to compromise legitimate Linux services. The activity appears focused on maintaining long-term access, conducting surveillance, harvesting credentials, executing commands, and manipulating web traffic while minimizing detection.[emaillocker id="1283"]
The attack chain appears to begin with compromise of an externally exposed Groupware or mail service, followed by persistence on an edge server and credential harvesting through an SSH keylogger. A stager profiles the compromised Linux host and selectively deploys trojanized versions of services such as crond, agetty, atd, polkitd, and HAProxy. curlRAT provides command execution, reverse-shell and interactive PTY capabilities, system reconnaissance, payload downloading, configuration updates, and C2 communication over HTTP/HTTPS using Base64 and XOR-based encryption. The Ted backdoor is particularly stealthy because it is compiled directly into HAProxy and hooks its HTTP-processing functionality to intercept traffic, capture selected HTTP headers and session information, execute attacker commands, transfer files, update configurations, and inject malicious scripts into webpages viewed by targeted users. It can also manipulate HAProxy connection statistics and terminate malicious C2 requests at the load balancer so that backend systems do not record the traffic.
The campaign represents a stealth-focused Linux intrusion framework capable of combining credential theft, persistent backdoor access, internal reconnaissance, command execution, traffic interception, and data theft within compromised infrastructure. Its integration into legitimate system services makes conventional file-based detection more difficult and allows malicious activity to blend with normal server operations. Organizations operating Linux-based edge servers, HAProxy infrastructure, groupware portals, and internet-facing services should monitor for unexpected modifications to system binaries, anomalous HAProxy behavior, unauthorized configuration files, suspicious outbound connections, credential harvesting activity, and unexplained changes to system logs.
THREAT PROFILE:
| Tactic | Technique Id | Technique | Sub-technique |
| Initial access | T1190 | Exploit Public | Facing Application- |
| Initial access | T1195 | Supply Chain Compromise | - |
| Execution | T1204.002 | User Execution | Malicious File |
| Persistence | T1543.003 | Create or Modify System Process | Windows Service |
| Defence Evasion | T1036.005 | Masquerading | Match Legitimate Resource Name or Location |
| Credential access | T1555.003 | Credentials from Password Stores | Credentials from Web Browsers |
| Collection | T1005 | Data from Local System | - |
| Collection | T1560.001 | Archive Collected Data | Archive via Utility |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | - |
MBC PROFILE:
| Objective | Behavior ID | Behavior |
| Command & Control | B0030 | C2 Communication |
| Impact | B0022 | Remote Access |
| Exfiltration | E1020 | Automated Exfiltration |
| Cryptography Micro-objective | C0031 | Decrypt Data |
| Discovery | E1083 | File and Directory Discovery |
| Anti-Static Analysis | B0032 | Executable Code Obfuscation |
| Anti-Static Analysis | E1027 | Obfuscated Files or Information |
| Execution | E1204 | User Execution |
| Persistence | F0012 | Registry Run Keys / Startup Folder |
REFERENCES:
The following reports contain further technical details:
https://www.rapid7.com/blog/post/tr-dprk-apts-ted-backdoor-curlrat-target-south-korean-media-automotive-sectors/