Security1 distinct publisher3 min readPublished
Rapid7 says the ted backdoor is built into the victim's existing HAProxy 2.8.12 and hooks its filter API, so the load balancer keeps balancing normally while it logs cookies and injects scripts for selected clients.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The operators' priorities show up in the watchdog. Rapid7 says the curl-based RAT that ships with this toolkit keeps a thread whose job is to track HAProxy's health and report it back to operator infrastructure [9]. The load balancer is the asset, and the rest of the kit exists just to keep it running and reachable.
The chain, as far as Rapid7 reconstructed it, runs through the edge box. Both victims exposed ports 80, 443 and 25, with a Groupware login portal on 443 and a mail server on 25 [5]. After the foothold, credentials come off that host, including plaintext passwords lifted by an SSH keylogger [14], and the same host doubles as the staging server for the trojanized system ELFs [13]. A stager then goes to internal servers, checks whether crond or HAProxy is present, and only then deploys CurlRAT, pulling it from its own data section or back from the edge webserver [15]. In parallel ted lands on the load balancer and opens its own C2 channel for exfiltration, command execution and injection [16]. Clients browsing through that balancer are then served the malicious content, which closes the watering-hole loop [17].
Rapid7's initial-access hypothesis leans on Kimsuky, which it says has been exploiting RCE flaws in externally accessible mail servers to compromise South Korean groupware vendors since the beginning of 2026 [12]. The attribution for the toolkit itself leans on C2 overlap with APT37 [11]. The report cites two separate DPRK clusters for two different parts of the same finding, and names no CVE for either.
On dating, the source gives two fixed points. The HAProxy 2.8.12-0fdb194 build was released on 22 November 2024, which is the earliest date the plugin could have been compiled against it [8], and the earliest VirusTotal uploads are mid-2025 [7]. That is a compile window of roughly seven months [20], against campaign activity Rapid7 places back to early 2025 [10].
What that leaves defenders is thin on indicators and specific on files. This material publishes one SHA-256, for the SSH keylogger [14]. A filter plugin built into the same service version the operator installed does not add a process to the process table, and legitimate load balancing keeps working while it runs [4]. So the check that matches the finding is comparing what is running on the edge against what the package should have put there: HAProxy first, then crond, agetty, atd, sshd and polkitd [2]. That gap means endpoint telemetry alone would not have surfaced this activity.
Rapid7 also says ted may belong to a wider framework that includes an nginx backdoor [19]. If that lands with samples, the same reasoning applies to a much larger installed base.
Ranked by verification strength, evidence, and original report placement.
The toolkit is attributed with medium confidence to DPRK APTs, based on the South Korean media and automotive victimology, simple xor-based encryption, a custom substitution cipher, and hardcoded C2s associated with APT37 by ThreatFox and maltrail.
Rapid7 Labs identified a new Linux toolkit targeting organizations across South Korea's automotive and media industries with minimal detection.
The campaign made use of a HAProxy instance named "ted backdoor", alongside trojanized versions of crond, agetty, atd, sshd and polkitd.
The framework enabled threat actors to execute remote commands on compromised servers, inject malicious scripts into web traffic, perform credential harvesting and engage in long-term surveillance.
The ted backdoor is compiled as part of the victim's existing HAProxy version 2.8.12 and uses its native filter API, internal memory pools, event scheduler and process management infrastructure to intercept traffic and hide from monitoring, while genuine load balancing traffic operates as expected.
At the time of analysis both victims were running an edge webserver with ports 80, 443 and 25 exposed; port 443 hosted the Groupware login portal and port 25 exposed a mail server.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 4, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
product
The renewal job goes green before the service ever reloads the certificate1 distinct publisher
build
SSE in Go breaks twice before your handler runs: an illegal header, then a 30-second timeout1 distinct publisher
security
Two Artifactory flaws poisoned metadata, not artifacts, and that was enough to break a shared cache1 distinct publisher
build
PyInstaller exits zero, then the real work starts: notarization traps that report success1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Deep artefacts, one pair of hands
The hard parts are unusually checkable: a specific build string (2.8.12-0fdb194), the keylogger's SHA-256, the encrypted log path, the single-byte XOR config, the CentOS 7.7-7.9 and Ubuntu 22.04 crond variants. All of it comes from Rapid7's own reverse engineering, and nobody in this story has looked at the same samples independently. Where the vendor moves from binaries to actors and entry points, the artefacts thin out and it says so.
Two victims, in the wild for a year
Real use is established rather than theorised: two compromised organizations, samples on VirusTotal from mid-2025, campaign activity Rapid7 dates to early 2025, and a stager built with pre-selected payloads for CentOS 7.7-7.9 and Ubuntu 22.04 — a toolkit made for repeat deployment. But the observed footprint is two victims in two sectors of one country, and no third party has reported seeing it elsewhere.
Actor named harder than proven
The mechanics are, if anything, undersold — a load balancer that passes traffic correctly while harvesting cookies and injecting scripts into selected sessions is a genuinely awkward detection problem, and it gets a paragraph. The overreach sits on the nameplate: DPRK operators lead the framing while the attribution is explicitly medium confidence and leans on community feeds tagging the C2s to APT37, with Kimsuky brought in by analogy to unrelated 2026 intrusions. Small gap, and it is in the attribution rather than the analysis.
Vendor research that admits its gaps
A detection vendor naming a previously undocumented framework gets marketing value from the naming, and Rapid7 is both the discoverer and the only witness here. Against that: the post publishes hashes and file paths rivals can use, sells nothing in the text we have, and volunteers that it cannot establish a timeline or initial access — the two things an incentive to overclaim would have papered over.
Solid on how, soft on who
Read this as reliable about the malware and provisional about the campaign. The binary analysis is specific, self-consistent and testable by anyone with the samples; the actor, the entry point and the start date rest on inference the vendor itself grades as unproven, and no independent account exists to raise or lower any of it.