DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

South Korean automotive and media organizations have been hit by a quiet Linux intrusion toolkit built for long-term access.

The malware hides inside software that manages web traffic, allowing attackers to watch users, steal information, and change pages delivered through compromised servers.

The operation appears designed for patience rather than disruption. Attackers likely entered through a groupware portal or mail server, used the edge server as a bridge into internal systems.

That pattern echoes the risks described in stealthy Linux server intrusions, where hidden access can remain active without drawing attention.

Analysts at Rapid7 identified the toolkit and assessed its link to DPRK-aligned advanced persistent threats with medium confidence.

Rapid7 said in a report shared with Cyber Security News (CSN) that the activity likely dates to early 2025, although the precise initial entry point and any exploited vulnerability have not been confirmed.

The affected organizations had ports 80, 443 and 25 exposed, with a groupware login service on port 443 and mail services on port 25.

Attack chain (Source - Rapid7)

These systems sit at the network edge, making their compromise serious: an intruder can collect credentials, move deeper inside, and potentially target visitors passing through that server.

DPRK-Linked Hackers Deploy Ted Backdoor

The central component, called ted backdoor, is a modified build of HAProxy 2.8.12, software commonly used to direct website traffic.

Instead of acting like a separate malicious program, it is compiled into the legitimate load balancer and uses its built-in features to inspect decrypted web requests while normal traffic continues to flow.

That placement gives the operators unusual control. The implant can capture session cookies and selected request details, run commands, upload or download files, and inject a malicious script into pages served to chosen visitors.

Its hidden command channel uses a request for a picture-like path, while its code also reduces HAProxy connection counters to make activity harder to spot. Researchers found an SSH keylogger as well as altered versions of crond, agetty, atd, sshd and polkitd.

The stager checks the operating system and whether HAProxy or cron is present before replacing the cron service, copying timestamps from a legitimate SSH binary, and removing chosen words from logs.

hardcoded master passwords in userauth_passwd() (Source - Rapid7)
hardcoded master passwords in userauth_passwd() (Source – Rapid7)

This reflects the same concern raised by Linux backdoors stealing SSH credentials: trusted system components can become the attacker’s hiding place.

CurlRAT supplies the remote-control layer. It polls attacker infrastructure for tasks, can execute commands, send system details, install added payloads, and open reverse or interactive shells with elevated privileges. A watchdog monitors HAProxy and reports whether the service starts, stops, reloads, or restarts.

Long-Term Espionage Risks and Defenses

Rapid7 said the combination of credential theft, web-session collection, selective page changes, and traffic redirection points to long-term espionage.

The targeting of South Korean media and automotive firms also fits a regional intelligence-gathering pattern. Readers following Kimsuky espionage activity in Korea will recognize why exposed groupware and stolen credentials remain valuable footholds.

The operators used basic XOR encryption and a substitution method to protect configurations and communications. Their command-and-control domains imitate image delivery services, including one that resembles a popular Korean web platform’s static-content naming style.

curlRAT configuration (Source - Rapid7)
curlRAT configuration (Source – Rapid7)

Rapid7 also noted overlap in timing and delivery concepts with other DPRK activity, but said more evidence is needed for a firmer attribution. Defenders should review edge systems that handle web traffic, encryption, mail, or runtime modules.

They should compare deployed HAProxy and Linux service binaries against known versions, inspect unexpected shared libraries and cron changes, and rotate credentials that may have passed through affected servers. Independent network monitoring matters because logs on a compromised device may have been altered.

Teams should also investigate unusual requests to image-like paths, unexpected outbound connections from load balancers, and web responses that change only for particular visitors.

Regular patching of groupware and mail servers reduces likely entry opportunities. As shown by recent Asia-focused Linux espionage, post-compromise tools can turn a single exposed server into a durable route across an organization.

Indicators of Compromise (IoCs):-

Type Indicator Description
SHA-256 5db1b6d52faf60b4f32d6fd0c7c938e4d05d29a14c32ded4a9668357c08b6a91 CurlRAT stager
SHA-256 09739441ed4599bac2f8159028f772f71e4b25c8badfff95574e56d7384f3dbe CurlRAT stager variant
SHA-256 fea1bc36632c71e5a839803469ef60ac47595d36b2c50934ac109ade6df06e61 CurlRAT stager variant
SHA-256 83f7d565b0465546027052b597af46eae3a199e7a91fcc2ab936341147349130 CurlRAT
SHA-256 7007a78d50a993cb174c685eba96eb442c9507e38fd9d8e5dffc712f613ec110 CurlRAT
SHA-256 6cf1b5e92a9c0756f597a5ddefb38eba32961c52efac7ab2a0aa52c639a8fc53 CurlRAT
SHA-256 ed72f4cd8d467b5c5d95ae6aeca4aaeea14d79565d379c1ca5871a714727be16 CurlRAT
SHA-256 feeea9d0bf6ae7396d28271baa51ae50df5169ce5d32a516865856f91abc50b3 CurlRAT
SHA-256 d53c760c23b4405eb04ad0f20ead375440344b3bdf1fb7854ed12e40d155eabe Trojanized cronie binary
SHA-256 2f02b09d61d432134e994ad671258f523bbf289ae6091fd4eae192c60bd51b6f Trojanized agetty binary
SHA-256 8f30b57928934ae67478d0e690c91d046e35a638da098d02922a4a88a0fdb66c Trojanized atd binary
SHA-256 a1d8af3a6acb731f07f72040eccb3450c1c83d40e29f736c2a63d35388660be4 Trojanized polkitd binary
SHA-256 12810854c8b2c391b23e2e18b013e873d0369b0637aa3cf993136c07188ba3b8 CurlRAT sample
SHA-256 009a1e2d7a582a24e50cf2ffc2a005482c8e38f22bf5ed416053855f8d054e1e CurlRAT sample
SHA-256 4bb923eb040aa13ca8fd409c31ee4729c60ddff32e350efe1c5a4a9168a065f5 SSH keylogger
SHA-256 94630b96f628c96a6bff7904b40ffc9ad67c86f8a4ff6080c3b524831c93f402 Ted backdoor
SHA-256 72e70936f0dbe459142a1d867617c35f8d0cce5d18c6a49e1090a2a5adc8e558 Modified HAProxy build containing ted backdoor
SHA-256 a8bfab4de81a1acb04aacdf757346946b0f5e30f0c9f402004016d0e425119c7 Ted backdoor sample
Domain img.monderhouse.space CurlRAT command-and-control infrastructure
Domain img.smartnords.site Command-and-control infrastructure
Domain img.darklights.store Backup CurlRAT configuration host
Domain img.responsive.pstatic.autos Command-and-control infrastructure masquerading as static content
Domain img.socialteams.store Command-and-control infrastructure
Domain img.worksongo.store Command-and-control infrastructure

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.

The post DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms appeared first on Cyber Security News.