Affected Systems

Two South Korean organizations in automotive and media sectors running compromised HAProxy load balancer binaries. The "ted" backdoor is compiled directly into trojanized HAProxy builds, not a vulnerability in legitimate HAProxy software. Requires prior root-level code execution to install.

Exploitation Status

Active exploitation confirmed at two South Korean organizations. Rapid7 attributes with medium confidence to North Korean state-sponsored actors (APT37/Lazarus/Kimsuky overlap). No public PoC; this is a targeted supply chain compromise requiring initial access and root privileges to replace legitimate binaries.

Business Impact

Organizations running compromised HAProxy instances face complete web traffic interception with no visibility in backend logs or load balancer statistics. Attackers can serve modified pages to targeted visitors, execute shell commands, and exfiltrate data through covert C2 channels disguised as normal HTTP traffic. The toolkit also includes trojanized sshd, crond, agetty, atd, and polkitd binaries that capture credentials and maintain persistence. Initial access vector remains unconfirmed but may involve exposed Korean Groupware portals.

Urgency

đź”´ Immediate

Recommended Actions

  • Verify integrity of HAProxy binaries against known-good hashes from official HAProxy repositories; check modification timestamps and compare file sizes
  • Inspect /tmp for named pipes and check for suspicious files at ~/cache/haproxy-1000.cache, /var/lib/sshd/c8c68e629bba773a10ac80012d10bf19, /var/lib/snapd/g580, and /tmp/jasper-log
  • Review historical DNS logs and proxy logs for connections to img.monderhouse[.]space, img.smartnords[.]site, img.darklights[.]store, img.responsive.pstatic[.]autos, img.socialteams[.]store, and img.worksongo[.]store
  • Audit system binaries crond, sshd, agetty, atd, and polkitd for unexpected modifications or timestamp anomalies (especially crond matching /usr/bin/ssh timestamp)
  • For South Korean organizations: assess exposure of Groupware portals and review authentication logs for unauthorized access; implement file integrity monitoring on critical system binaries

---

# Geopolitical Context

Geopolitical Context

The discovery of the "ted" backdoor in trojanized HAProxy load balancers at South Korean automotive and media organizations is consistent with a sustained pattern of North Korean cyber operations targeting critical infrastructure in the Republic of Korea. Rapid7 attributes the toolkit with medium confidence to North Korean state-sponsored actors, drawing on infrastructure overlaps with APT37 and operational similarities to Lazarus and Kimsuky campaigns. The targeting of automotive and media sectors aligns with Pyongyang's documented intelligence collection priorities and its strategic interest in South Korean industrial capabilities and information environments. The supply-chain compromise methodology—replacing legitimate system binaries with trojanized versions—reflects an advanced persistent threat posture requiring prior network access and elevated privileges, suggesting a multi-stage intrusion campaign. The operational security measures, including C2 traffic disguised as ordinary web requests and erasure from load balancer statistics, indicate sophisticated tradecraft aimed at long-term persistence. This incident occurs within the broader context of inter-Korean tensions and North Korea's reliance on cyber operations as a low-cost, high-impact asymmetric capability for espionage, disruption, and revenue generation.

State Actor Alignment

Rapid7 attributes the "ted" backdoor toolkit with medium confidence to North Korean state-sponsored actors based on infrastructure overlaps with APT37 (also known as Reaper, ScarCruft), operational delivery models resembling Lazarus Group campaigns (specifically Operation SyncHole), and initial-access hypotheses consistent with Kimsuky tactics documented in prior Groupware compromises. All six C2 domains identified in the campaign appear in maltrail's APT37 infrastructure listings and ThreatFox records from July 2025. The attribution assessment acknowledges the challenge posed by shared tooling and overlapping targeting across North Korean cyber units, as documented in Mandiant's 2023 assessment of DPRK cyber structure. The Democratic People's Republic of Korea remains under comprehensive international sanctions, including UN Security Council resolutions and bilateral measures by the United States, European Union, and allied nations targeting its cyber programs. South Korea maintains active cyber defense cooperation with the United States through the bilateral alliance framework and participates in multilateral threat intelligence sharing arrangements.

Business Impacty pro region

The targeting of South Korean automotive and media organizations carries implications for both regional security and global supply chains. The automotive sector represents a critical component of South Korea's export economy and is deeply integrated into international manufacturing networks, raising concerns about potential intellectual property theft, industrial espionage, or future supply-chain compromises affecting downstream partners in North America, Europe, and Asia-Pacific markets. Media sector targeting suggests intelligence collection objectives related to information operations, journalist surveillance, or preparation for influence campaigns—consistent with North Korean efforts to monitor and shape narratives regarding the peninsula. For the broader Indo-Pacific region, the incident underscores persistent cyber threats to U.S. treaty allies and the need for enhanced collective defense mechanisms. European organizations with South Korean partnerships in automotive manufacturing, technology development, or media collaboration should review their exposure to compromised infrastructure and assess third-party risk. The use of trojanized system binaries rather than zero-day exploits suggests that basic security hygiene—including binary integrity verification, privileged access management, and anomaly detection—remains essential across all sectors and geographies facing advanced persistent threats.

Forecast

If North Korean cyber operations continue to prioritize South Korean critical infrastructure and employ supply-chain compromise techniques, defenders should anticipate further discoveries of trojanized system components in enterprise environments, particularly where initial access may have occurred through vulnerable collaboration software or exposed enterprise portals. If the Groupware initial-access hypothesis is validated, organizations using Korean enterprise collaboration platforms are likely to face heightened targeting, and vendors may accelerate security reviews and patch cycles. If attribution confidence strengthens through additional infrastructure correlation or technical overlap with known North Korean toolsets, international coordination on sanctions enforcement and threat intelligence sharing is likely to intensify, particularly within the U.S.-ROK alliance framework and Five Eyes partnerships. If the automotive sector targeting reflects industrial espionage objectives, South Korean and international manufacturers may implement enhanced insider threat programs and supply-chain security controls to mitigate risks of intellectual property exfiltration. If media sector compromises enable surveillance of journalists or preparation for information operations, press freedom organizations and democratic governments may increase support for secure communications and digital safety training in the region. The operational security sophistication demonstrated—including C2 traffic disguised within legitimate web flows and erasure from logging infrastructure—suggests that detection will require behavioral analytics and anomaly detection rather than signature-based approaches, driving continued investment in advanced threat hunting capabilities.